CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — Week of August 24, 2026
Issued: Monday, August 24, 2026 | Audience: Federal Contractors, DevOps, Security Operations
CISA added eight vulnerabilities to the KEV catalog across the past week, spanning enterprise collaboration platforms, VPN infrastructure, AI/ML development toolchains, and Oracle middleware. Several deadlines have already passed or expire today, demanding immediate triage. The entries cluster into three operationally meaningful themes: deadline-critical infrastructure flaws, a coordinated assault on AI and developer tooling, and unauthenticated remote access vulnerabilities requiring network-level containment.
Deadline Watch: Oracle, Microsoft, and Zimbra
The most time-sensitive entries this week center on widely deployed enterprise infrastructure, and several remediation windows have already closed or expire today.
CVE-2026-55040 (Microsoft SharePoint) and CVE-2026-33824 (Microsoft IKE Service Extensions) both carried a patch deadline of August 21—three days ago. If your SharePoint or IKE deployments have not been patched, treat them as compromised until forensic triage confirms otherwise. The SharePoint weak authentication vulnerability allows unauthenticated network-based bypass of security controls, a straightforward entry point for lateral movement in any environment where SharePoint is federated with Active Directory or Entra ID. The IKE double-free vulnerability is particularly alarming given IKE's role in VPN tunnel establishment—successful exploitation could yield remote code execution against a service running at the kernel boundary on Windows hosts, potentially before any user interaction. Federal contractors operating under BOD 26-04 must document remediation or compensating controls for both.
CVE-2026-73570 (Zimbra Collaboration Suite) had its deadline on August 24—today. This OS command injection flaw is unauthenticated and exploitable via specially crafted SMTP requests, meaning any internet-facing Zimbra MTA is a candidate for blind exploitation without credentials. Zimbra has historically been a high-priority target for nation-state actors; the combination of unauthenticated access and OS-level command execution as the Zimbra user should be treated as a complete server compromise scenario. If patching cannot be completed today, isolate the SMTP listener behind an application-aware mail gateway and review all Zimbra-generated process logs for anomalous child processes spawned from the MTA service.
CVE-2026-21962 (Oracle HTTP Server and WebLogic Server Proxy Plug-in) was added to the KEV today with an extraordinarily compressed three-day deadline of August 27. This improper access control vulnerability allows unauthorized read, create, modify, and delete access to all data accessible through the proxy plug-in—effectively a complete confidentiality and integrity failure for any WebLogic deployment behind Oracle HTTP Server. Organizations running Oracle Fusion Middleware stacks should treat this as an emergency change window. Verify whether the proxy plug-in is exposed externally; if so, prioritize patching above all other work this week. BOD 22-01 cloud guidance applies where OHS or WebLogic is hosted in IaaS environments.
Developer Toolchain Under Siege: AI/ML Infrastructure Actively Targeted
A second and increasingly significant pattern this week is the targeting of machine learning and distributed compute infrastructure—systems that DevOps and data engineering teams frequently treat as lower-security internal tooling.
CVE-2026-64849 (MLflow) is a server-side request forgery vulnerability with a deadline of September 2. SSRF in an MLflow deployment is not a low-severity finding: MLflow servers are frequently deployed in cloud environments with access to instance metadata services (AWS IMDS, Azure IMDS, GCP metadata). Successful exploitation means an attacker can retrieve cloud credentials, IAM roles, and internal service endpoints with nothing more than network access to the MLflow UI. If MLflow is reachable from the internet or from shared developer workstations, treat it as an immediate credential exposure risk. Rotate any cloud credentials associated with the MLflow server role and audit metadata service access controls regardless of whether patching is complete.
CVE-2025-62593 (Ray-Project Ray) had a patch deadline of August 21, now passed. Ray's code injection vulnerability is exploitable through Firefox and Safari, meaning developers who simply browse to a Ray dashboard on a shared or developer network can trigger remote code execution. Ray clusters are often co-located with model weights, training data, and production API keys. Any Ray installation that was internet-accessible or reachable from shared developer networks prior to patching should be subject to full forensic triage. Audit Ray job histories and connected object stores for signs of data exfiltration.
Unauthenticated Network Access: TrueConf's Dual Exposure
CVE-2026-72529 and CVE-2026-72530 both affect TrueConf Server and were added to the KEV on August 20. The two vulnerabilities operate as a natural chain: CVE-2026-72529 (missing authentication for a critical function) allows a remote attacker with network access to port 4307/TCP to execute arbitrary scripts without credentials. CVE-2026-72530 (code injection) then enables escape from the isolated execution environment to arbitrary code execution on the host. Together, they represent a full remote-to-host compromise path requiring only TCP reachability to port 4307.
The deadlines differ—August 23 for CVE-2026-72529 (now passed) and September 3 for CVE-2026-72530—but operationally, both must be patched together to close the attack chain. If TrueConf Server cannot be patched immediately, block port 4307/TCP at the network perimeter and on host-based firewalls. Treat any TrueConf Server that was exposed on port 4307 to untrusted networks as a host-level compromise until forensic triage under BOD 26-04's Forensics Triage Requirements is complete.
Summary Deadline Table
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | 2026-08-21 | OVERDUE | | CVE-2026-55040 | Microsoft SharePoint | 2026-08-21 | OVERDUE | | CVE-2025-62593 | Ray | 2026-08-21 | OVERDUE | | CVE-2026-72529 | TrueConf Server | 2026-08-23 | OVERDUE | | CVE-2026-73570 | Zimbra ZCS | 2026-08-24 | DUE TODAY | | CVE-2026-21962 | Oracle HTTP/WebLogic | 2026-08-27 | 3 days | | CVE-2026-64849 | MLflow | 2026-09-02 | 9 days | | CVE-2026-72530 | TrueConf Server | 2026-09-03 | 10 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Oracle Critical Patch Update Advisory · Zimbra Security Advisories · Microsoft Security Update Guide · MLflow Security Disclosures · Ray Security Advisories · TrueConf Security Bulletins
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 24, 2026
Federal Agencies Issue Alert on AI-Assisted Attacks Targeting Industrial Control Systems
Five federal agencies released a joint cybersecurity advisory warning that unspecified threat actors are conducting AI-assisted attacks against Siemens S7 Series programmable logic controllers at critical infrastructure facilities across the United States. The advisory represents the first confirmed government acknowledgment of artificial intelligence being weaponized to target industrial control systems in active campaigns. The attacks focus on PLCs widely deployed in energy, manufacturing, and water treatment facilities, suggesting sophisticated threat actors are leveraging AI capabilities to automate reconnaissance, vulnerability discovery, or exploitation of operational technology environments. The warning comes as the UAE separately reports defending against approximately 800,000 daily hacking attempts—four times pre-conflict levels—using its own AI-powered defensive systems.
Novel FTP Banner Technique Delivers Malware in Ongoing Campaign
Threat actors are exploiting File Transfer Protocol server banners to hide malware commands and infect Windows systems in a campaign active since early July. The technique abuses FTP banner messages—typically used to display server information—to inject and execute malicious payloads, representing a creative evasion method that bypasses traditional detection focused on file transfers or standard command-and-control channels. The campaign continues to target Windows environments with no identified attribution. Separately, a hacker group identifying itself as "Madarx" claims to be selling six million Bangladeshi job seeker CVs on dark web marketplaces, while Apollo Global reportedly suffered a data breach exposing names, addresses, and Social Security numbers after attackers accessed the firm's cloud infrastructure.
Sources: SC World · Rest of World · Techzine Global · New Age · IDN Financials
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Canvas is back in the classroom despite security concerns following hack - Cardinal News
In April, hackers breached Instructure, the company behind Canvas, which schools use to manage assignments, track grades and deliver course content, ....
Iran-linked hackers blamed for power pant shut down - Energy Live News
Iran-linked hackers have been blamed for a cyber-attack that temporarily shut down a small UK power plant, reports the Guardian.
After raising $51 million, Minimus shuts down as Twistlock founders return remaining | Ctech
The cybersecurity startup failed to gain enough commercial momentum to continue operating. Customers will have 60 days to migrate before the ...
Lazarus Group Exploits Windows Zero-Day to Target Defense and Aerospace
The North Korean Lazarus Group exploited a newly patched Windows zero-day to deliver a never-before-seen backdoor targeting defense and aerospace comp...
Microsoft Patches Critical Entra ID Remote Code Execution Vulnerability CVE-2026-69836
Microsoft patched a critical remote code execution vulnerability in Entra ID (CVSS 10.0) that allows unauthorized attackers to execute code over a net...
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web ...
Iranian hackers carry out unprecedented attack on UK's power network - The Independent
Iranian hackers carry out unprecedented attack on UK's power network · The generator was forced to shut down for four days following the cyber ...
Iranian hackers forced UK energy facility to shut for four days - The Times
Iranian hackers shut down a British energy facility for four days last month in what is believed to be the first attack of its kind in this ...
Updated daily
