- Details
- 2026-08-31 10:26:04
Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes
Subscribe to get these articles directly to your inbox when published
| Metric | Value |
| Total new KEV additions this month | 31 |
| CVSS Critical entries (9.0–10.0) | 12 |
| CVSS High entries (7.0–8.9) | 14 |
| Entries with confirmed active exploitation | 31 |
| Entries with public PoC or exploit code | 22 |
| Most affected vendor | Microsoft (5 entries) |
| Most common exploitation type | Remote Code Execution (RCE) / Code Injection |
| Sectors most targeted | Government / FCEB, Technology / SaaS, Healthcare |
| CVE | Vendor / Product | CVSS | Type | Why It's Priority |
| CVE-2026-82078 | PaperCut NG/MF | 9.4 | Unsafe Reflection / RCE | Unsafe dynamic reflection allows remote bytecode execution; widely deployed in education/enterprise printing infrastructure and heavily targeted for initial access. |
| CVE-2026-81578 | PaperCut NG/MF | 9.8 | Auth Bypass | Missing authentication for critical administrative functions allows unauthenticated system reconfiguration, frequently chained with RCE vectors. |
| CVE-2023-49105 | ownCloud | 9.8 | Auth Bypass | WebDAV API authentication bypass exposes sensitive file storage without credentials; actively leveraged by APT groups to exfiltrate critical data. |
| CVE-2026-59310 | Broadcom VMware vCenter | 9.8 | Path Traversal / RCE | Unauthenticated path traversal in core virtualization management interface grants threat actors full administrative hypervisor domain compromise. |
| CVE-2026-73570 | Synacor Zimbra Collaboration Suite | 9.8 | Command Injection | Unauthenticated crafted SMTP requests yield remote shell access on edge mail infrastructure, posing immediate email exfiltration threats. |
| CVE-2026-8037 | Progress LoadMaster | 9.8 | Command Injection | Unsanitized input exploitation on perimeter load balancers permits complete appliance takeover prior to internal network expansion. |
| CVE-2026-9198 | IBM / Langflow | 9.8 | Code Injection | Default AI agent deployments contain zero-click remote code execution vulnerabilities, exposing downstream API keys and ML pipelines. |
| CVE-2026-63077 | JetBrains TeamCity | 9.8 | Deserialization / RCE | Unauthenticated agent polling protocol exploitation exposes CI/CD build environments to malicious code execution and supply chain contamination. |
| CVE-2026-18577 | N-able N-central | 9.8 | Auth Bypass | Incomplete path filtering lets unauthenticated users bypass authentication entirely, giving attackers full access to MSP management tools. |
| CVE-2026-65400 | Apple macOS | 9.0 | Auth Bypass | Network protocol vulnerability permits credential-less authentication to Screen Sharing, opening lateral movement paths across macOS endpoints. |
Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities. View all weekly reports here
The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
August's threat landscape demonstrates a targeted push toward perimeter management software, virtualization layers, and developer automation tooling. Attackers continue to show elevated sophistication by prioritizing remote authentication bypasses and command injection flaws on appliances that lack endpoint detection agent visibility. A distinct shift is visible in the targeting of AI pipelines and developer platforms (such as IBM Langflow, MLflow, and Ray-Project) alongside managed service provider (MSP) software like N-able N-central. Threat actors are aggressively capitalizing on historical legacy vulnerabilities (e.g., CVE-2015-3246 and CVE-2023-49105), proving that unpatched legacy software remains a viable initial access route alongside zero-day or recent disclosure exploitation.
| Sector | Exposure Level | Key CVEs This Month | Recommended Focus |
| Government / FCEB | High | CVE-2023-49105, CVE-2026-8452, CVE-2026-55040 | Enforce immediate patching on self-hosted cloud storage and edge VPN/ADC endpoints. |
| Healthcare | High | CVE-2026-82078, CVE-2026-81578, CVE-2026-59310 | Isolate print server VLANs and apply hypervisor management network segmentation. |
| Financial Services | Medium | CVE-2019-1068, CVE-2026-33824, CVE-2026-21962 | Audit internal database engines and WebLogic proxy configurations for unauthenticated access. |
| Critical Infrastructure | High | CVE-2026-20349, CVE-2026-8037, CVE-2026-53362 | Patch edge firewalls, load balancers, and Linux kernel networking dependencies immediately. |
| Technology / SaaS | High | CVE-2026-63077, CVE-2025-62593, CVE-2026-9198 | Secure developer build agents, ML execution nodes, and internal code-signing infrastructure. |
August’s KEV additions expose a dangerous operational myth: that internal, non-internet-facing applications like print servers, ML pipelines, and local build agents can wait for standard monthly patch cycles. The simultaneous targeting of developer frameworks (Ray-Project, Langflow) alongside infrastructure tools (PaperCut, N-central) indicates that threat actors are intentionally targeting the trusted administrative layer to achieve silent enterprise-wide access.
Furthermore, CISA's catalog additions this month act as lag indicators for machine-driven exploitation sweeps—by the time vulnerabilities like CVE-2023-49105 or CVE-2026-82078 hit the KEV, automated scanning scripts are already conducting mass exfiltration. Organizations must shift away from reactive, CVSS-only remediation models and immediately prioritize patching any asset listed in the KEV that intersects with identity networks, internal tools, or remote management access.
This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available.
Timur Mehmet | Founder & Lead Editor
Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.
Contact:
This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:
Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections
Learn More: About Hackerstorm.com | FAQs
CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
National Vulnerability Database (NVD): https://nvd.nist.gov/
PaperCut Security Advisories: https://www.papercut.com/kb/Main/SecurityAdvisories/
VMware / Broadcom Security Advisories: https://support.broadcom.com/group/ecx/security-advisories
N-able Security Advisories: https://me.n-able.com/s/security-advisories
HackerStorm Threat Intelligence Field Notes (August 2026)
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.