This month: 18 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-73570
Synacor · Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Detected Aug 21 · 3-day patch deadline
CVE-2026-72529
TrueConf · Server
TrueConf Server Missing Authentication for Critical Function Vulnerability
Detected Aug 20 · 3-day patch deadline
CVE-2025-62593
Ray-Project · Ray
Ray-Project Ray Code Injection Vulnerability
Detected Aug 18 · 3-day patch deadline

KEV Intelligence Brief — August 21, 2026

Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Distribution: TLP:WHITE Reporting Period: August 18–21, 2026

Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog over the past four days span infrastructure virtualization, enterprise collaboration, AI/ML developer tooling, and core Windows network services. The pattern is notable: threat actors are actively pivoting across the full stack, from developer workstations to hypervisor control planes. Federal civilian agencies operating under BOD 26-04 face legally binding remediation deadlines — several of which expire today. All other organizations should treat these with equivalent urgency.

Deadline Watch: Today's Expiry Cluster Demands Immediate Action

Four CVEs carry a patch deadline of August 21, 2026 — meaning remediation windows close as of this brief's publication.

CVE-2026-33824 (Microsoft IKE Service Extensions) is arguably the most structurally dangerous of the group. A double-free memory corruption vulnerability in the Internet Key Exchange service creates a remote code execution pathway in Windows environments with IPsec/VPN exposed to the network. IKE is rarely considered an attack surface by perimeter teams, yet it sits at the heart of encrypted tunnel negotiation in hybrid-cloud and zero-trust architectures. Organizations should verify that IKE endpoints are not directly reachable from untrusted networks and apply the relevant Windows security update immediately.

CVE-2026-55040 (Microsoft SharePoint) describes a weak authentication vulnerability that allows unauthenticated network attackers to bypass security controls. SharePoint is pervasive in government and federal contractor environments, frequently handling sensitive unclassified documents and serving as an identity-integrated collaboration hub. Authentication bypass on SharePoint can chain directly into credential harvesting, lateral movement, or data exfiltration — particularly dangerous in hybrid Microsoft 365 deployments where on-premise SharePoint federates with cloud identity. Teams running on-premise SharePoint servers should treat any unpatched instance as externally compromised until patched and forensically triaged per BOD 26-04 requirements.

CVE-2026-59310 (Broadcom VMware vCenter) adds a path traversal vulnerability enabling arbitrary code execution for any attacker with network-level access to vCenter. vCenter exploits consistently represent some of the highest-impact incidents in enterprise environments because successful exploitation gives adversaries hypervisor-level control over entire virtual infrastructure estates. The blast radius here is enormous. Organizations should immediately audit vCenter network exposure, enforce management-plane network segmentation if not already in place, rotate vCenter service account credentials, and apply Broadcom's patch without delay. Cloud environments managed through vCenter-compatible APIs should be evaluated per BOD 26-04 cloud service guidance.

CVE-2025-62593 (Ray-Project Ray) rounds out today's expired deadlines with a code injection vulnerability affecting the Ray distributed computing framework, exploitable through Firefox and Safari. Ray is widely used in AI/ML research and production inference pipelines. The browser-exploitable nature of this flaw is atypical and significant: developers running Ray dashboards locally or on shared development infrastructure are exposed through routine web browsing. This is a supply-chain and developer-endpoint risk, not just a server risk.

The AI/ML Attack Surface Expands: Developer Tooling in the Crosshairs

The simultaneous KEV listing of two AI/ML platform vulnerabilities — Ray (CVE-2025-62593) and MLflow (CVE-2026-64849) — signals that adversaries are actively targeting the machine learning development lifecycle, not just production deployments.

MLflow's server-side request forgery vulnerability (CVE-2026-64849, deadline September 2) is particularly high-value in cloud-native ML environments. An SSRF in MLflow can be weaponized to reach AWS Instance Metadata Service (IMDS), Azure IMDS, or GCP metadata endpoints, harvesting cloud credentials and enabling lateral movement far beyond the ML platform itself. Organizations running MLflow on cloud infrastructure should immediately enforce IMDSv2 with hop-limit restrictions, block MLflow's egress to internal metadata IP ranges (169.254.169.254, fd00:ec2::254), and evaluate whether MLflow instances are inadvertently internet-exposed. Credential rotation for any cloud roles accessible from MLflow hosts is strongly advised regardless of confirmed exploitation.

For Ray (CVE-2025-62593), teams should audit all Ray cluster dashboard ports for external exposure, restrict dashboard binding to loopback or internal-only interfaces, and ensure developer machines are not running unpatched Ray versions while using affected browsers. Given Ray's prevalence in both research and production AI inference, security teams should treat any Ray deployment as potentially affected until patched.

Collaboration Infrastructure Under Pressure: TrueConf and Zimbra

Three CVEs target enterprise communication and collaboration platforms, and together they form an alarming chain for organizations running unified communications infrastructure.

The two TrueConf Server vulnerabilities — CVE-2026-72529 (missing authentication, deadline August 23) and CVE-2026-72530 (code injection, deadline September 3) — both operate through port 4307/TCP and require no authentication to reach. CVE-2026-72529 allows unauthenticated script execution; CVE-2026-72530 allows sandbox breakout and host-level code execution. Chained together, these two flaws constitute a complete unauthenticated RCE path to the underlying host. Any organization with TrueConf Server exposed — even on internal networks — should immediately firewall port 4307 from all but explicitly required sources, apply available patches, and conduct forensic triage for signs of prior exploitation consistent with BOD 26-04 requirements. Discontinue use if vendor patches are unavailable.

CVE-2026-73570 (Zimbra Collaboration Suite, deadline August 24) enables OS command injection via unauthenticated SMTP requests, with commands executing as the Zimbra service user. Zimbra has been a recurring KEV target due to its prevalence in government and international organizational deployments. Unauthenticated SMTP injection is particularly severe because SMTP is an operationally required open port; organizations cannot simply firewall it away. Apply the vendor patch on an emergency basis, review Zimbra process execution logs for anomalous child processes, and ensure outbound SMTP relay rules do not permit lateral pivot.

Summary Remediation Priorities

| CVE | Product | Deadline | Priority | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | Aug 21 — TODAY | Critical | | CVE-2026-55040 | Microsoft SharePoint | Aug 21 — TODAY | Critical | | CVE-2026-59310 | VMware vCenter | Aug 21 — TODAY | Critical | | CVE-2025-62593 | Ray | Aug 21 — TODAY | High | | CVE-2026-72529 | TrueConf Server | Aug 23 | Critical | | CVE-2026-73570 | Zimbra ZCS | Aug 24 | Critical | | CVE-2026-64849 | MLflow | Sep 2 | High | | CVE-2026-72530 | TrueConf Server | Sep 3 | High |

All deadlines are binding for federal civilian agencies under BOD 26-04. Non-federal organizations should apply equivalent urgency to any internet-facing or internally critical instances.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Broadcom VMware Security Advisories · Microsoft Security Response Center · Synacor Zimbra Security Advisories · MLflow Security Disclosures · Ray-Project Security Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 21, 2026

Active SharePoint Exploitation and PLM Attacks Target Enterprise Infrastructure

CISA has confirmed active exploitation of CVE-2026-45659, a recently patched remote code execution vulnerability in Microsoft SharePoint. The agency's warning indicates threat actors are moving quickly to weaponize the flaw against unpatched enterprise deployments. Separately, the ransomware group Clop has exploited vulnerabilities in product lifecycle management (PLM) software to compromise manufacturing giants including Shell, GE, and Philips. The campaign demonstrates continued threat actor focus on supply chain and enterprise management platforms as high-value targets for data exfiltration and ransomware deployment.

Multi-Agent AI Attack Confirmed Against Asia-Pacific Government

A Chinese-language threat actor has successfully executed what security researchers are describing as a multi-agent AI attack against government agencies in the Asia-Pacific region. The incident represents documented evidence of near-autonomous AI-enabled offensive operations moving from theoretical capability to active deployment. In related AI-enabled threat activity, unknown attackers attempted to compromise security researchers using a fabricated cryptocurrency conference as a lure, underscoring threat actor interest in targeting security professionals directly. Meanwhile, a Trezor hardware wallet vulnerability (CVE-2026-20685) exposed customer data across multiple countries between May and August 2026, affecting users of the cryptocurrency storage platform.

Sources: Security Week · Smart Industry · Cadre · TechCrunch · The Hacker News

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://cisoseries.comAug 21

Will AI Replace Detection Roles in Cybersecurity? - CISO Series

Will AI eliminate detection engineering jobs, or just the busywork? Security leaders weigh in on where automation actually stops.

https://techcrunch.comAug 21

Someone targeted security researchers using a fake crypto conference as a lure

If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good ...

https://www.ctvnews.caAug 21

How a Texas student blew the whistle on a rogue AI hacking attempt: Reuters exclusive

The 24-year-old native of Turkiye figured he had caught a wily hacker red-handed. So he said he was shocked when Britain's AI Security Institute (AISI...

https://www.highereddive.comAug 21

DOJ charges 17 in Iran-backed hacking campaign against US colleges, others

Officials allege the Mabna Institute was behind an effort to steal research from American universities, companies and government agencies.

https://cybersecuritynews.comAug 20

T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network

T-Mobile's security team physically severed a network cable at a Seattle data center to expel Chinese state-backed hackers from Salt Typhoon, part of ...

https://thehackernews.comAug 19

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A previously unreported China-nexus cyber espionage operation dubbed SilkParasite is actively targeting government organizations across Central Asia u...

https://thehackernews.comAug 21

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

... Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental ...

https://www.gatech.eduAug 20

Georgia Tech Students Claim Victory at DEF CON's Elite Hacking Competition

Year after year, some of the world's best hackers gather at DEF CON in Las Vegas to put their skills to the test. None is more prominent than the ...


Updated daily