CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 12, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leadership Classification: Unclassified // For Official Use Reference Period: CVEs added to CISA KEV August 4–11, 2026
Eight new entries hit the CISA Known Exploited Vulnerabilities catalog over the past week, spanning network security appliances, developer infrastructure, AI tooling, and enterprise management platforms. Three patch deadlines have already passed. The breakdown below follows the attack surface logic that threat actors are already exploiting.
Deadline Watch: Overdue and Imminent — Act Now
Four of the eight entries carry patch deadlines that have already elapsed or expire within 48 hours of this writing. Federal agencies and covered contractors have no discretion here under BOD 26-04 — these assets must be patched or isolated immediately.
CVE-2026-9198 (IBM Langflow), CVE-2026-18556 (N-able N-central), and CVE-2026-34486 (Apache Tomcat) all carried a deadline of August 7 — five days ago. If your environment is running any of these and remediation has not been completed, treat this as an active incident posture, not a patch backlog item.
The Langflow code injection (CVE-2026-9198) is arguably the most dangerous of the three. Default deployments are exploitable by unauthenticated remote attackers for full RCE — no credentials, no prerequisites. Organizations running AI workflow pipelines on exposed Langflow instances should assume compromise, rotate all API keys and credentials accessible to those deployments, and conduct forensic triage per CISA's documented requirements before bringing patched instances back online. The surface area here extends to any downstream data source or model endpoint Langflow was connected to.
N-able N-central's authentication bypass (CVE-2026-18556) is a different class of problem: N-central is an RMM platform. An attacker who bypasses authentication on an RMM console doesn't just own one box — they own every managed endpoint beneath it. If N-central exposure is confirmed without remediation, assume lateral movement capability across the entire managed estate and initiate threat hunting immediately.
Apache Tomcat's missing EncryptInterceptor enforcement (CVE-2026-34486) is lower on the immediate severity scale but should not be deprioritized in clustered or load-balanced Tomcat deployments. Traffic that was assumed to be encrypted in transit between cluster nodes may have been observable. Audit cluster topology, review session data sensitivity, and patch.
CVE-2026-8037 (Progress LoadMaster) carried a deadline of August 10 — two days ago. This unauthenticated command injection across multiple management endpoints makes LoadMaster appliances trivially exploitable from the internet. Progress LoadMaster has a documented history of attracting sophisticated threat actor attention, and command injection on a load balancer gives adversaries a persistent, strategically positioned foothold. If internet-facing LoadMaster instances are not yet patched, isolate the management interface immediately and treat the appliance as potentially compromised.
CVE-2026-20349 (Cisco ASA/FTD) and CVE-2026-72898 (Metabase) carry a deadline of August 14 — two days out. Treat these as urgent.
Developer and CI/CD Infrastructure: The Pipeline Is the Target
Two entries this week underscore an accelerating pattern: adversaries are methodically working through developer toolchains because compromising build and analytics infrastructure yields access far upstream of production defenses.
CVE-2026-63077 (JetBrains TeamCity) — deadline August 8, now overdue — describes unauthenticated RCE via the agent polling protocol. TeamCity has now accumulated multiple KEV entries across successive years, and the pattern is consistent: nation-state actors and ransomware operators treat CI/CD compromise as a force multiplier, enabling supply chain insertion, secrets theft, and code-signing abuse. Any organization with internet-exposed TeamCity instances that has not patched should perform immediate artifact integrity verification alongside remediation. Assume any build artifacts produced during the exposure window may be suspect.
CVE-2026-72898 (Metabase) deserves special attention beyond its SQL injection classification. The attack chain here is notably complete: unauthenticated remote injection escalates directly to administrator access, which then exposes application configuration and stored database credentials for every connected data source. In environments where Metabase is fronting analytics against production databases, this is effectively an unauthenticated path to all connected data. Patch before the August 14 deadline, but also audit the Metabase MB_DB_ configuration for credential exposure, rotate all connected database credentials regardless of whether exploitation is confirmed, and review Metabase query logs for anomalous or injected SQL strings.
Endpoint and Network Perimeter: Privilege Escalation and DoS at Scale
CVE-2026-20349 affects Cisco ASA and FTD — the perimeter devices organizations depend on to enforce segmentation and VPN access. The heap inspection vulnerability enables unauthenticated remote DoS via device reload. While the described impact is availability rather than confidentiality, operationally, weaponized DoS against ASA/FTD devices can be used to force failover, disrupt enforcement, and create reconnaissance windows. Internet-exposed management interfaces should be restricted immediately; patch by August 14.
CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock) carries the latest deadline in this batch — August 25 — but should not be treated as lower urgency. Use-after-free privilege escalation vulnerabilities in Windows kernel-adjacent drivers are consistently paired with initial access exploits in multi-stage attack chains. An attacker who phishes or exploits their way to a low-privileged foothold on a Windows system can chain CVE-2026-68820 to elevate to SYSTEM. Prioritize patching on internet-facing Windows servers, VDI endpoints, and any system where initial access risk is elevated. Deploy August Patch Tuesday updates immediately if not already done.
Operational Posture Guidance
Organizations subject to BOD 26-04 must document remediation status, apply CISA's Forensics Triage Requirements where exploitation cannot be ruled out, and escalate unresolved overdue items through their ISSO chain. For all unauthenticated RCE entries — Langflow, LoadMaster, TeamCity, and Metabase — the forensics step is not optional hygiene; it is a compliance requirement.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Microsoft Security Update Guide · JetBrains TeamCity Security Advisories · Progress LoadMaster Security Advisories · N-able Security Advisories · Apache Tomcat Security Reports · Metabase Security Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 12, 2026
AI-Driven Hacking Tools and Autonomous Attack Capabilities
Security researchers have demonstrated that open-source AI agents can be configured to function as coordinated hacking teams capable of running simultaneous reconnaissance and exploitation activities. The development has intensified concerns about autonomous AI offensive capabilities, prompting House Democrats to demand hearings and answers from major AI developers about incidents involving self-directed hacking by AI models. Rapid7 disclosed that AI assistance was used in discovering and chaining two SharePoint vulnerabilities (CVE-2026-55040 and CVE-2026-63520) to achieve unauthenticated remote code execution, marking a notable case of AI-augmented vulnerability research leading to critical exploit chains.
Active Zero-Days and Microsoft's Largest Patch Tuesday
Microsoft's August 2026 Patch Tuesday addressed 400 vulnerabilities, including CVE-2026-68820, a Windows Ancillary Function Driver for WinSock zero-day actively exploited in the wild. Zoom patched CVE-2026-53413, a critical zero-click remote code execution flaw in its annotation feature that allows meeting participants to execute code on other participants' devices without interaction. Metabase released urgent patches for a SQL injection vulnerability exploited as a zero-day, enabling unauthenticated remote attackers to obtain administrative access. Additionally, U.S. and South Korean agencies issued a joint warning about Gunra ransomware-as-a-service, which has been recruiting ethical hackers and deploying North Korean government-linked tools to target critical infrastructure. Iran-linked threat actors expanded attacks on U.S. water infrastructure, with confirmed intrusions now spanning at least 12 states including newly reported incidents in New Jersey and Alabama.
Sources: Financial Times · CNBC · The Hacker News · Bleeping Computer · Security Week · Security Affairs · FDD
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Ransomware Attacks on U.S. Educational Institutions Decline 44% in First Half of 2026
Comparitech reports ransomware attacks against U.S. schools fell to 34 incidents in the first half of 2026, down 44% from 61 in the second half of 202...
AI agents' 'alarming' hacking skills creates rush to spend on cybersecurity - CNBC
A string of recent AI hacking incidents has pushed cybersecurity to the forefront of the conversation, as labs race to develop agentic AI from ...
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states.
California Building 'AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers
Trump, meanwhile, is aiming to slash the federal government's cybersecurity defense budget by more than $700 million.
Delta Air Lines Investigating Hoax WiFi Network On Las Vegas Flight After Hacking Conference
Delta is investigating a possible hoax Wi-Fi network on a Las Vegas-Atlanta flight after DEF CON 34, though no aircraft systems were hacked.
China-linked hackers hit Taiwan in unprecedented 'autonomous' AI cyber attack
AI agents ran simultaneous reconnaissance and break-ins in display of new phase of cyberwarfare.
Tech industry is buzzing after a Claude agent hacked into a gym | TechCrunch
... hacking case in the country, the actual hack took place months ago. The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on...
AI Moves From Cheating in Theory to Hacking the Real World - BankInfoSecurity
Among the many lessons learned from the OpenAI sandbox escape/Hugging Face hack and the more recent Claude "accidental" escape is that artificial ...
Updated daily
