This month: 19 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-21962
Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Detected Aug 24 · 3-day patch deadline
CVE-2026-73570
Synacor · Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Detected Aug 21 · 3-day patch deadline
CVE-2026-72529
TrueConf · Server
TrueConf Server Missing Authentication for Critical Function Vulnerability
Detected Aug 20 · 3-day patch deadline

KEV Intelligence Brief — Week of August 24, 2026

Issued: Monday, August 24, 2026 | Audience: Federal Contractors, DevOps, Security Operations

CISA added eight vulnerabilities to the KEV catalog across the past week, spanning enterprise collaboration platforms, VPN infrastructure, AI/ML development toolchains, and Oracle middleware. Several deadlines have already passed or expire today, demanding immediate triage. The entries cluster into three operationally meaningful themes: deadline-critical infrastructure flaws, a coordinated assault on AI and developer tooling, and unauthenticated remote access vulnerabilities requiring network-level containment.

Deadline Watch: Oracle, Microsoft, and Zimbra

The most time-sensitive entries this week center on widely deployed enterprise infrastructure, and several remediation windows have already closed or expire today.

CVE-2026-55040 (Microsoft SharePoint) and CVE-2026-33824 (Microsoft IKE Service Extensions) both carried a patch deadline of August 21—three days ago. If your SharePoint or IKE deployments have not been patched, treat them as compromised until forensic triage confirms otherwise. The SharePoint weak authentication vulnerability allows unauthenticated network-based bypass of security controls, a straightforward entry point for lateral movement in any environment where SharePoint is federated with Active Directory or Entra ID. The IKE double-free vulnerability is particularly alarming given IKE's role in VPN tunnel establishment—successful exploitation could yield remote code execution against a service running at the kernel boundary on Windows hosts, potentially before any user interaction. Federal contractors operating under BOD 26-04 must document remediation or compensating controls for both.

CVE-2026-73570 (Zimbra Collaboration Suite) had its deadline on August 24—today. This OS command injection flaw is unauthenticated and exploitable via specially crafted SMTP requests, meaning any internet-facing Zimbra MTA is a candidate for blind exploitation without credentials. Zimbra has historically been a high-priority target for nation-state actors; the combination of unauthenticated access and OS-level command execution as the Zimbra user should be treated as a complete server compromise scenario. If patching cannot be completed today, isolate the SMTP listener behind an application-aware mail gateway and review all Zimbra-generated process logs for anomalous child processes spawned from the MTA service.

CVE-2026-21962 (Oracle HTTP Server and WebLogic Server Proxy Plug-in) was added to the KEV today with an extraordinarily compressed three-day deadline of August 27. This improper access control vulnerability allows unauthorized read, create, modify, and delete access to all data accessible through the proxy plug-in—effectively a complete confidentiality and integrity failure for any WebLogic deployment behind Oracle HTTP Server. Organizations running Oracle Fusion Middleware stacks should treat this as an emergency change window. Verify whether the proxy plug-in is exposed externally; if so, prioritize patching above all other work this week. BOD 22-01 cloud guidance applies where OHS or WebLogic is hosted in IaaS environments.

Developer Toolchain Under Siege: AI/ML Infrastructure Actively Targeted

A second and increasingly significant pattern this week is the targeting of machine learning and distributed compute infrastructure—systems that DevOps and data engineering teams frequently treat as lower-security internal tooling.

CVE-2026-64849 (MLflow) is a server-side request forgery vulnerability with a deadline of September 2. SSRF in an MLflow deployment is not a low-severity finding: MLflow servers are frequently deployed in cloud environments with access to instance metadata services (AWS IMDS, Azure IMDS, GCP metadata). Successful exploitation means an attacker can retrieve cloud credentials, IAM roles, and internal service endpoints with nothing more than network access to the MLflow UI. If MLflow is reachable from the internet or from shared developer workstations, treat it as an immediate credential exposure risk. Rotate any cloud credentials associated with the MLflow server role and audit metadata service access controls regardless of whether patching is complete.

CVE-2025-62593 (Ray-Project Ray) had a patch deadline of August 21, now passed. Ray's code injection vulnerability is exploitable through Firefox and Safari, meaning developers who simply browse to a Ray dashboard on a shared or developer network can trigger remote code execution. Ray clusters are often co-located with model weights, training data, and production API keys. Any Ray installation that was internet-accessible or reachable from shared developer networks prior to patching should be subject to full forensic triage. Audit Ray job histories and connected object stores for signs of data exfiltration.

Unauthenticated Network Access: TrueConf's Dual Exposure

CVE-2026-72529 and CVE-2026-72530 both affect TrueConf Server and were added to the KEV on August 20. The two vulnerabilities operate as a natural chain: CVE-2026-72529 (missing authentication for a critical function) allows a remote attacker with network access to port 4307/TCP to execute arbitrary scripts without credentials. CVE-2026-72530 (code injection) then enables escape from the isolated execution environment to arbitrary code execution on the host. Together, they represent a full remote-to-host compromise path requiring only TCP reachability to port 4307.

The deadlines differ—August 23 for CVE-2026-72529 (now passed) and September 3 for CVE-2026-72530—but operationally, both must be patched together to close the attack chain. If TrueConf Server cannot be patched immediately, block port 4307/TCP at the network perimeter and on host-based firewalls. Treat any TrueConf Server that was exposed on port 4307 to untrusted networks as a host-level compromise until forensic triage under BOD 26-04's Forensics Triage Requirements is complete.

Summary Deadline Table

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | 2026-08-21 | OVERDUE | | CVE-2026-55040 | Microsoft SharePoint | 2026-08-21 | OVERDUE | | CVE-2025-62593 | Ray | 2026-08-21 | OVERDUE | | CVE-2026-72529 | TrueConf Server | 2026-08-23 | OVERDUE | | CVE-2026-73570 | Zimbra ZCS | 2026-08-24 | DUE TODAY | | CVE-2026-21962 | Oracle HTTP/WebLogic | 2026-08-27 | 3 days | | CVE-2026-64849 | MLflow | 2026-09-02 | 9 days | | CVE-2026-72530 | TrueConf Server | 2026-09-03 | 10 days |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Oracle Critical Patch Update Advisory · Zimbra Security Advisories · Microsoft Security Update Guide · MLflow Security Disclosures · Ray Security Advisories · TrueConf Security Bulletins

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 24, 2026

Federal Agencies Issue Alert on AI-Assisted Attacks Targeting Industrial Control Systems

Five federal agencies released a joint cybersecurity advisory warning that unspecified threat actors are conducting AI-assisted attacks against Siemens S7 Series programmable logic controllers at critical infrastructure facilities across the United States. The advisory represents the first confirmed government acknowledgment of artificial intelligence being weaponized to target industrial control systems in active campaigns. The attacks focus on PLCs widely deployed in energy, manufacturing, and water treatment facilities, suggesting sophisticated threat actors are leveraging AI capabilities to automate reconnaissance, vulnerability discovery, or exploitation of operational technology environments. The warning comes as the UAE separately reports defending against approximately 800,000 daily hacking attempts—four times pre-conflict levels—using its own AI-powered defensive systems.

Novel FTP Banner Technique Delivers Malware in Ongoing Campaign

Threat actors are exploiting File Transfer Protocol server banners to hide malware commands and infect Windows systems in a campaign active since early July. The technique abuses FTP banner messages—typically used to display server information—to inject and execute malicious payloads, representing a creative evasion method that bypasses traditional detection focused on file transfers or standard command-and-control channels. The campaign continues to target Windows environments with no identified attribution. Separately, a hacker group identifying itself as "Madarx" claims to be selling six million Bangladeshi job seeker CVs on dark web marketplaces, while Apollo Global reportedly suffered a data breach exposing names, addresses, and Social Security numbers after attackers accessed the firm's cloud infrastructure.

Sources: SC World · Rest of World · Techzine Global · New Age · IDN Financials

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://cardinalnews.orgAug 24

Canvas is back in the classroom despite security concerns following hack - Cardinal News

In April, hackers breached Instructure, the company behind Canvas, which schools use to manage assignments, track grades and deliver course content, ....

https://www.energylivenews.comAug 24

Iran-linked hackers blamed for power pant shut down - Energy Live News

Iran-linked hackers have been blamed for a cyber-attack that temporarily shut down a small UK power plant, reports the Guardian.

https://www.calcalistech.comAug 24

After raising $51 million, Minimus shuts down as Twistlock founders return remaining | Ctech

The cybersecurity startup failed to gain enough commercial momentum to continue operating. Customers will have 60 days to migrate before the ...

https://thehackernews.comAug 21

Lazarus Group Exploits Windows Zero-Day to Target Defense and Aerospace

The North Korean Lazarus Group exploited a newly patched Windows zero-day to deliver a never-before-seen backdoor targeting defense and aerospace comp...

https://cyberrecaps.comAug 22

Microsoft Patches Critical Entra ID Remote Code Execution Vulnerability CVE-2026-69836

Microsoft patched a critical remote code execution vulnerability in Entra ID (CVSS 10.0) that allows unauthorized attackers to execute code over a net...

https://thehackernews.comAug 24

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web ...

https://www.the-independent.comAug 23

Iranian hackers carry out unprecedented attack on UK's power network - The Independent

Iranian hackers carry out unprecedented attack on UK's power network · The generator was forced to shut down for four days following the cyber ...

https://www.thetimes.comAug 23

Iranian hackers forced UK energy facility to shut for four days - The Times

Iranian hackers shut down a British energy facility for four days last month in what is believed to be the first attack of its kind in this ...


Updated daily