Our Blog

Hackerstorm monthly KEV vulnerability report

HackerStorm Vulnerability Priority Report – August 2026

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

Subscribe to get these articles directly to your inbox when published

 

 

31 KEV additions. 12 critical CVEs. 
 

The Month in Numbers

 

Metric Value
Total new KEV additions this month 31
CVSS Critical entries (9.0–10.0) 12
CVSS High entries (7.0–8.9) 14
Entries with confirmed active exploitation 31
Entries with public PoC or exploit code 22
Most affected vendor Microsoft (5 entries)
Most common exploitation type Remote Code Execution (RCE) / Code Injection
Sectors most targeted Government / FCEB, Technology / SaaS, Healthcare

 

 

Priority Vulnerabilities This Month

 

CVE Vendor / Product CVSS Type Why It's Priority
CVE-2026-82078 PaperCut NG/MF 9.4 Unsafe Reflection / RCE Unsafe dynamic reflection allows remote bytecode execution; widely deployed in education/enterprise printing infrastructure and heavily targeted for initial access.
CVE-2026-81578 PaperCut NG/MF 9.8 Auth Bypass Missing authentication for critical administrative functions allows unauthenticated system reconfiguration, frequently chained with RCE vectors.
CVE-2023-49105 ownCloud 9.8 Auth Bypass WebDAV API authentication bypass exposes sensitive file storage without credentials; actively leveraged by APT groups to exfiltrate critical data.
CVE-2026-59310 Broadcom VMware vCenter 9.8 Path Traversal / RCE Unauthenticated path traversal in core virtualization management interface grants threat actors full administrative hypervisor domain compromise.
CVE-2026-73570 Synacor Zimbra Collaboration Suite 9.8 Command Injection Unauthenticated crafted SMTP requests yield remote shell access on edge mail infrastructure, posing immediate email exfiltration threats.
CVE-2026-8037 Progress LoadMaster 9.8 Command Injection Unsanitized input exploitation on perimeter load balancers permits complete appliance takeover prior to internal network expansion.
CVE-2026-9198 IBM / Langflow 9.8 Code Injection Default AI agent deployments contain zero-click remote code execution vulnerabilities, exposing downstream API keys and ML pipelines.
CVE-2026-63077 JetBrains TeamCity 9.8 Deserialization / RCE Unauthenticated agent polling protocol exploitation exposes CI/CD build environments to malicious code execution and supply chain contamination.
CVE-2026-18577 N-able N-central 9.8 Auth Bypass Incomplete path filtering lets unauthenticated users bypass authentication entirely, giving attackers full access to MSP management tools.
CVE-2026-65400 Apple macOS 9.0 Auth Bypass Network protocol vulnerability permits credential-less authentication to Screen Sharing, opening lateral movement paths across macOS endpoints.

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

Threat Landscape Context

August's threat landscape demonstrates a targeted push toward perimeter management software, virtualization layers, and developer automation tooling. Attackers continue to show elevated sophistication by prioritizing remote authentication bypasses and command injection flaws on appliances that lack endpoint detection agent visibility. A distinct shift is visible in the targeting of AI pipelines and developer platforms (such as IBM Langflow, MLflow, and Ray-Project) alongside managed service provider (MSP) software like N-able N-central. Threat actors are aggressively capitalizing on historical legacy vulnerabilities (e.g., CVE-2015-3246 and CVE-2023-49105), proving that unpatched legacy software remains a viable initial access route alongside zero-day or recent disclosure exploitation.

 

 

Sector Exposure Summary

 

Sector Exposure Level Key CVEs This Month Recommended Focus
Government / FCEB High CVE-2023-49105, CVE-2026-8452, CVE-2026-55040 Enforce immediate patching on self-hosted cloud storage and edge VPN/ADC endpoints.
Healthcare High CVE-2026-82078, CVE-2026-81578, CVE-2026-59310 Isolate print server VLANs and apply hypervisor management network segmentation.
Financial Services Medium CVE-2019-1068, CVE-2026-33824, CVE-2026-21962 Audit internal database engines and WebLogic proxy configurations for unauthenticated access.
Critical Infrastructure High CVE-2026-20349, CVE-2026-8037, CVE-2026-53362 Patch edge firewalls, load balancers, and Linux kernel networking dependencies immediately.
Technology / SaaS High CVE-2026-63077, CVE-2025-62593, CVE-2026-9198 Secure developer build agents, ML execution nodes, and internal code-signing infrastructure.

 

Hackerstorm Analysis

 

August’s KEV additions expose a dangerous operational myth: that internal, non-internet-facing applications like print servers, ML pipelines, and local build agents can wait for standard monthly patch cycles. The simultaneous targeting of developer frameworks (Ray-Project, Langflow) alongside infrastructure tools (PaperCut, N-central) indicates that threat actors are intentionally targeting the trusted administrative layer to achieve silent enterprise-wide access.

 

Furthermore, CISA's catalog additions this month act as lag indicators for machine-driven exploitation sweeps—by the time vulnerabilities like CVE-2023-49105 or CVE-2026-82078 hit the KEV, automated scanning scripts are already conducting mass exfiltration. Organizations must shift away from reactive, CVSS-only remediation models and immediately prioritize patching any asset listed in the KEV that intersects with identity networks, internal tools, or remote management access.

 

 


 

About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy