This month: 17 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-72529
TrueConf · Server
TrueConf Server Missing Authentication for Critical Function Vulnerability
Detected Aug 20 · 3-day patch deadline
CVE-2025-62593
Ray-Project · Ray
Ray-Project Ray Code Injection Vulnerability
Detected Aug 18 · 3-day patch deadline
CVE-2026-33824
Microsoft · Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Detected Aug 18 · 3-day patch deadline

KEV Intelligence Brief — August 20, 2026

Issued by: Security Operations Intelligence | Classification: TLP:WHITE Coverage Period: August 18–20, 2026 | CVEs Covered: 8

CISA added eight vulnerabilities to the KEV catalog over the past 72 hours spanning five vendors, three architectural layers, and multiple exploitation surfaces. The entries cluster into three distinct threat narratives: a cascade of critical Microsoft and VMware infrastructure flaws demanding immediate action, an aggressive attack surface emerging across AI/ML and video conferencing developer tooling, and a credential bypass flaw targeting macOS endpoints at scale. Federal agencies and contractors operating under BOD 26-04 face hard patch deadlines as early as Friday, August 21 — some effectively overdue by the time this brief is read.

Deadline Watch: Microsoft, VMware, and Apple — Friday Is Not Optional

Three vendors account for five of this week's KEV additions, all carrying a patch deadline of August 21, 2026 — tomorrow. Organizations that have not already begun remediation are operationally behind.

CVE-2026-33824 (Microsoft IKE Service Extensions) is a double-free vulnerability enabling remote code execution within Windows VPN infrastructure. Double-free conditions in kernel-adjacent components are notoriously reliable primitives for privilege escalation chains; treat this as a potential beachhead into broader Windows environments, not merely a VPN issue. IKE services are frequently exposed at network perimeters and between network segments, amplifying blast radius.

CVE-2026-55040 (Microsoft SharePoint) describes a weak authentication bypass allowing unauthenticated network access to bypass a security feature. SharePoint is pervasive in federal contractor environments and frequently holds sensitive documents and integrated workflows. An authentication bypass here isn't a theoretical risk — it is an active credential-free path into organizational data stores. Teams running on-premises SharePoint should treat this as emergency-tier; SharePoint Online operators should verify Microsoft's service-side remediation status and consult tenant security advisories.

CVE-2026-59310 (Broadcom VMware vCenter) is a path traversal vulnerability permitting arbitrary code execution for any threat actor with network access to vCenter. VMware vCenter vulnerabilities have a documented history of rapid weaponization by nation-state and ransomware actors. Network-level access to vCenter — often assumed to be an internal-only risk — is increasingly achievable through earlier-stage footholds. If your vCenter management interface is not strictly isolated from general corporate network segments, that architectural gap is now your most urgent compensating control, independent of patching timeline.

CVE-2026-65400 (Apple macOS) enables a network-adjacent attacker to authenticate to Screen Sharing without valid credentials. This is a credential-less remote control capability. In enterprise environments where macOS endpoints are common among engineering and executive staff, this vulnerability provides an interactive foothold requiring no phishing, no malware delivery, and no password. Organizations should immediately audit Screen Sharing enablement across the fleet and disable the service where it is not operationally required, even before patch deployment. Credential rotation for accounts on affected systems is strongly advised.

All four require patching by August 21 under BOD 26-04. Contracting officers and security leads should document remediation progress now for audit purposes.

AI/ML and Developer Tooling Under Active Exploitation

Two vulnerabilities this week reinforce an accelerating pattern: the AI/ML development stack is under sustained, active attack, and the assumption that developer tools are "internal" or "low-risk" is no longer defensible.

CVE-2025-62593 (Ray-Project Ray) is a code injection vulnerability enabling remote code execution, with a notable detail: it is exploitable through Firefox and Safari in developer contexts. Ray is widely used to orchestrate distributed machine learning workloads. The browser-based exploitation vector means developers who interact with Ray dashboards — even on local or lab networks — may be exposed without running traditional server-facing services. The patch deadline is August 21, and teams using Ray in any capacity should treat browser-accessible Ray UI components as a high-priority attack surface. Network segmentation of Ray clusters and disabling browser-accessible dashboards where feasible are warranted compensating controls.

CVE-2026-64849 (MLflow) is a server-side request forgery (SSRF) vulnerability allowing attackers to pivot to internal services and cloud metadata endpoints, capturing response status and body content. In cloud-hosted ML pipeline environments, metadata service access — particularly the IMDSv1 endpoint on AWS or equivalent GCP/Azure services — can yield instance credentials sufficient for lateral movement or privilege escalation within a cloud tenant. The patch deadline is September 2, offering slightly more runway, but the cloud metadata exfiltration angle makes this a higher-urgency item than the timeline implies. MLflow instances should have outbound network access restricted via egress firewall rules, and cloud metadata service access should be blocked at the host or network level as an immediate compensating control regardless of patch status.

TrueConf Server: A Two-Stage Attack Chain to Watch

CVE-2026-72529 and CVE-2026-72530 (TrueConf Server) are distinct vulnerabilities on the same product and same attack surface — port 4307/TCP — and they appear designed to function as a two-stage compromise chain. CVE-2026-72529 is a missing authentication flaw enabling arbitrary script execution by any unauthenticated remote attacker; CVE-2026-72530 is a code injection vulnerability that breaks out of TrueConf's isolated environment to execute arbitrary code on the host operating system.

Read together: an attacker who achieves script execution via the authentication bypass (72529) can leverage the code injection (72530) to escape containment and own the underlying host. The patch deadlines differ — August 23 for CVE-2026-72529 and September 3 for CVE-2026-72530 — but the chained exploitation risk means both should be treated as a single emergency. Port 4307 should be firewalled from any public or untrusted network segment immediately. TrueConf Server deployments that cannot be patched within this window should be taken offline or strictly access-controlled until remediation is confirmed.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft Security Response Center · Broadcom VMware Security Advisories · Apple Security Updates · Ray-Project Security · MLflow Security Advisories · TrueConf Security Bulletins

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 21, 2026

Active SharePoint Exploitation and PLM Attacks Target Enterprise Infrastructure

CISA has confirmed active exploitation of CVE-2026-45659, a recently patched remote code execution vulnerability in Microsoft SharePoint. The agency's warning indicates threat actors are moving quickly to weaponize the flaw against unpatched enterprise deployments. Separately, the ransomware group Clop has exploited vulnerabilities in product lifecycle management (PLM) software to compromise manufacturing giants including Shell, GE, and Philips. The campaign demonstrates continued threat actor focus on supply chain and enterprise management platforms as high-value targets for data exfiltration and ransomware deployment.

Multi-Agent AI Attack Confirmed Against Asia-Pacific Government

A Chinese-language threat actor has successfully executed what security researchers are describing as a multi-agent AI attack against government agencies in the Asia-Pacific region. The incident represents documented evidence of near-autonomous AI-enabled offensive operations moving from theoretical capability to active deployment. In related AI-enabled threat activity, unknown attackers attempted to compromise security researchers using a fabricated cryptocurrency conference as a lure, underscoring threat actor interest in targeting security professionals directly. Meanwhile, a Trezor hardware wallet vulnerability (CVE-2026-20685) exposed customer data across multiple countries between May and August 2026, affecting users of the cryptocurrency storage platform.

Sources: Security Week · Smart Industry · Cadre · TechCrunch · The Hacker News

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://cisoseries.comAug 21

Will AI Replace Detection Roles in Cybersecurity? - CISO Series

Will AI eliminate detection engineering jobs, or just the busywork? Security leaders weigh in on where automation actually stops.

https://techcrunch.comAug 21

Someone targeted security researchers using a fake crypto conference as a lure

If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good ...

https://www.ctvnews.caAug 21

How a Texas student blew the whistle on a rogue AI hacking attempt: Reuters exclusive

The 24-year-old native of Turkiye figured he had caught a wily hacker red-handed. So he said he was shocked when Britain's AI Security Institute (AISI...

https://www.highereddive.comAug 21

DOJ charges 17 in Iran-backed hacking campaign against US colleges, others

Officials allege the Mabna Institute was behind an effort to steal research from American universities, companies and government agencies.

https://cybersecuritynews.comAug 20

T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network

T-Mobile's security team physically severed a network cable at a Seattle data center to expel Chinese state-backed hackers from Salt Typhoon, part of ...

https://thehackernews.comAug 19

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A previously unreported China-nexus cyber espionage operation dubbed SilkParasite is actively targeting government organizations across Central Asia u...

https://thehackernews.comAug 21

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

... Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental ...

https://www.gatech.eduAug 20

Georgia Tech Students Claim Victory at DEF CON's Elite Hacking Competition

Year after year, some of the world's best hackers gather at DEF CON in Las Vegas to put their skills to the test. None is more prominent than the ...


Updated daily