CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 3, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leadership Classification: TLP:CLEAR | For general distribution
Network Infrastructure Under Active Siege: Authentication and Access Control Failures Across the Perimeter
The most operationally critical cluster in this week's KEV additions targets the devices and management planes that organizations trust most: firewalls, SD-WAN orchestrators, and endpoint management platforms. Three entries demand immediate attention, and two of their deadlines have already passed.
CVE-2026-20316 (Cisco Secure Firewall Management Center) is the most straightforward and arguably the most damaging: a hard-coded password embedded in FMC allows an unauthenticated remote attacker to log in with a low-privileged account and access sensitive data. Hard-coded credentials are trivially weaponized — no exploit sophistication required, and detection is minimal since the login appears legitimate. The patch deadline was August 1, making this overdue for any federal or federal-adjacent organization. If your FMC instance is internet-exposed, treat it as potentially compromised and initiate forensic triage per BOD 26-04 requirements before applying the patch.
CVE-2026-16812 (Arista VeloCloud Orchestrator On-Prem) presents an OS command injection path that gives remote attackers privileged access to internal orchestrator functionality — effectively full control over the SD-WAN fabric and the network topology data it manages. The patch deadline was July 30, meaning remediation is three days overdue as of today. SD-WAN orchestrators are high-value targets because lateral movement from the orchestrator to managed edge devices is often trivial. If patching is delayed for operational reasons, isolate the VCO management interface from untrusted networks immediately and audit all recent administrative sessions.
CVE-2026-16232 (Check Point SmartConsole) rounds out this cluster: improper authentication allows an unauthenticated attacker to obtain a login token and authenticate with full administrative privileges to the firewall management console. The July 25 deadline has passed. Organizations relying on SmartConsole for policy management should rotate all administrative credentials, review token issuance logs for anomalous activity, and restrict SmartConsole access to management-only VLANs or jump hosts. Granting unauthenticated actors full admin rights to a firewall is a network-wide event, not a single-system compromise.
Deadline Watch: Incomplete Patches, Persistent Post-Exploit Mechanisms, and RCE in Collaboration Tools
Three entries this week share a particularly troubling characteristic: they involve either bypasses of previous fixes or vulnerability classes historically associated with ransomware and nation-state pre-positioning.
CVE-2026-18577 (N-able N-central) was added to KEV today, August 3, with an aggressive three-day patch window expiring August 6. This is explicitly an incomplete patch for CVE-2026-18556 — meaning threat actors have already reverse-engineered the original fix and found an alternate authentication bypass path. RMM platforms like N-central are perennial targets because compromising the management layer compromises every endpoint it manages. Organizations must apply the new patch, not assume the previous remediation was sufficient. Conduct a full review of any accounts created or modified in N-central since CVE-2026-18556 was first patched; account takeover in RMM tools frequently precedes mass ransomware deployment.
CVE-2025-68686 (Fortinet FortiOS) carries a patch deadline of August 10 — the furthest out in this batch — but don't let that lull teams into complacency. This vulnerability allows a remote unauthenticated attacker to bypass Fortinet's own remediation for the symbolic link persistence mechanism previously documented in post-exploitation cases. That means attackers who already established persistence via an earlier FortiOS compromise may retain a covert foothold even after organizations believed they had cleaned the environment. The forensic implication is significant: any FortiOS device previously assessed as clean following earlier Fortinet campaigns should be re-evaluated. CISA's Forensics Triage Requirements under BOD 26-04 are directly applicable here.
CVE-2026-50522 (Microsoft SharePoint) closed its patch window on July 25 and describes a deserialization of untrusted data vulnerability enabling unauthenticated remote code execution over the network. SharePoint deserialization vulnerabilities have a well-documented history of exploitation by both criminal ransomware groups and APT actors for initial access into enterprise environments. Any internet-facing SharePoint deployment that has not yet applied Microsoft's patch should be treated as a priority incident. Credential harvesting and lateral movement to Azure-connected resources are the most likely follow-on actions; review SharePoint audit logs and OAuth token issuance for anomalies dating back to late July.
Emerging and Long-Tail Targets: AI Tooling and Embedded Router Firmware
Two entries represent different ends of the exposure spectrum but share the characteristic of being overlooked in standard vulnerability management programs.
CVE-2026-0770 (Langflow) allows remote code execution via inclusion of functionality from an untrusted control sphere — a class of vulnerability particularly dangerous in AI workflow orchestration tools, where arbitrary code execution in the pipeline context can compromise model inputs, training data, and downstream API integrations. The July 24 deadline has passed. DevOps and MLOps teams adopting Langflow for agentic or RAG workflows should patch immediately, restrict the Langflow interface to internal networks only, and audit pipeline configurations for injected or modified components.
CVE-2021-27137 (DD-WRT) is a five-year-old stack-based buffer overflow in the UPnP stack, now confirmed exploited in the wild and added to KEV on July 21 with a July 24 deadline. DD-WRT appears in home routers, small office environments, and some OT-adjacent network segments. Its presence in KEV in 2026 signals active threat actor interest — likely targeting remote workers or branch office infrastructure as an initial access vector. UPnP should be disabled on any DD-WRT device that cannot immediately receive firmware updates, and organizations should audit their asset inventories for consumer-grade router firmware in environments handling sensitive data.
Recommended Immediate Actions
- Overdue deadlines (CVE-2026-20316, CVE-2026-16812, CVE-2026-16232, CVE-2026-50522, CVE-2021-27137, CVE-2026-0770): Escalate to incident response posture; patch or isolate now, initiate forensic triage per BOD 26-04.
- August 6 deadline (CVE-2026-18577): Emergency patching sprint this week; assume prior N-central remediation is insufficient.
- August 10 deadline (CVE-2025-68686): Re-assess all previously remediated FortiOS devices for residual persistence before patching.
- Rotate credentials on all affected platforms regardless of confirmed exploitation status.
- Document compliance actions and retain forensic artifacts as required under BOD 26-04.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory — FMC · Fortinet PSIRT Advisories · Microsoft Security Update Guide — SharePoint · Check Point Security Advisories · Arista Security Advisories · N-able Security Advisories · CISA Langflow Alert
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 3, 2026
Water Infrastructure Attacks Spread as FBI Expands Investigation
The campaign targeting U.S. water utilities through internet-connected programmable logic controllers (PLCs) continues to escalate, prompting a joint FBI and EPA warning about ongoing operational disruptions. Federal agencies report that attackers are compromising internet-exposed industrial control systems to gain unauthorized access, leading to service interruptions at multiple facilities. The investigation has expanded beyond the previously identified Iranian-linked campaign as additional incidents emerge nationwide, though authorities have not disclosed the full scope of affected systems or whether new threat actors are involved.
Active Exploitation of N-able, Cisco, and SharePoint Vulnerabilities
Attackers are actively exploiting CVE-2026-18577, an authentication bypass vulnerability in N-able N-Central that enables remote administrative access to managed endpoints. The vendor released patches on August 2. CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-20316 affecting Cisco Secure Firewall Management Center, which contains static credentials, and CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint that threat actors are now exploiting in the wild. Marketing platform Klue confirmed attackers used compromised legacy credentials to steal OAuth tokens and access customer data stored in Salesforce and Gong instances. Separately, researchers disclosed three high-severity flaws in Hugging Face's Diffusers library that could enable arbitrary code execution when loading malicious AI model repositories. The disclosure follows earlier reports of AI models breaching organizations during security testing, with Anthropic confirming three of its Claude models compromised unnamed organizations due to configuration errors.
Cryptocurrency Cold Wallet Attack Campaign Targets Hardware Devices
Hackers are conducting an ongoing campaign exploiting a software flaw in Bitcoin cold wallet hardware, traditionally considered one of the most secure cryptocurrency storage methods. Attackers are using automated "Seed-Entropy Sweep" tools to compromise wallet seed phrases and exfiltrate funds from offline storage devices. The campaign represents a significant shift in cryptocurrency theft tactics, moving beyond exchange compromises to target hardware wallet implementations. In an unrelated incident, Liechtenstein authorities disclosed that attackers illegally accessed the country's beneficial ownership register, compromising data on approximately 31,000 legal entities. Brinks Home confirmed a breach discovered July 20 affecting up to 5 million customer records, one week after attackers claimed access to data on 1.1 million clients.
Sources: Industrial Cyber · The Hacker News · Security Week · Data Breach Today · Bloomberg · Reuters · Inc
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Coinkite tells owners with exposed seeds to generate a new one on patched firmware and move their coins. Cybersecurity. Restoring the old seed to ...
Anthropic's Claude hacked three real-life companies during security capabilities test
Impressive hacking skills on display, but the incidents illustrate a lack of 101-level cybersecurity practices.
Why would Russian hackers target a water treatment plant in eastern Quebec? | CBC.ca
... residents in eastern Quebec. Its mayor, Gilbert Marquis, says the hackers didn't access any sensitive information and the water remains potable.
AI agents spark concerns over 'going rogue,' hacking companies | Fox News Video
AI agents spark concerns over 'going rogue,' hacking companies. AI Policy Network's Mark Beall joins 'Saturday in America' to discuss the threat of .....
Cybersecurity expert explains cyber threats facing Wisconsin water systems - TMJ4 News
Cybersecurity expert Alex Holden says Wisconsin utilities are facing growing cyber threats after hackers disrupted water operations in neighboring ...
Cyberattacks Hit Water Facilities In Seven States Across The US - Engadget
The FBI has issued a warning after water facilities from seven states reported that they were hacked ... hacking campaign that CISA previously describ...
7 States' Water Systems Hit by Cyberattacks Likely Tied to Iran | WIRED
The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital ...
FBI: Hackers Targeted Water Utility Providers in at Least 7 States | PCMag
Hackers have been targeting internet-exposed computers known as programmable logic controllers, causing 'loss of pressure and flooding,' the FBI ...
Updated daily
