Summary
The Known Exploited Vulnerability (KEV) catalog, maintained by CISA, is the authoritative source of vulnerabilities that have been exploited in the wild. It is recommended that all organizations review and monitor the KEV catalog, prioritize remediation of listed vulnerabilities, and reduce the likelihood of compromise by threat actors. In August 2026, 31 vulnerabilities met the criteria for inclusion in CISA’s KEV catalog. Of these, 4 are zero-day vulnerabilities; 12 have been exploited by a threat actor and employed in attacks.
CVEs List
| CVE ID | Name | Affected Product | CVSS 3.x | Due Date |
|---|---|---|---|---|
CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | PaperCut NG/MF | 9.1 | September 14, 2026 |
CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | PaperCut NG/MF | 9.8 | September 14, 2026 |
CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | ownCloud | 9.8 | August 30, 2026 |
CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | Linux Kernel | 7.8 | August 30, 2026 |
CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | JFrog Artifactory | 5.3 | September 10, 2026 |
CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | Ajax.NET Professional | 9.8 | September 09, 2026 |
CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | Red Hat Libuser | 5.1 | September 09, 2026 |
CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | Red Hat Automatic Bug Reporting Tool | 7.8 | September 09, 2026 |
CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | Linux Kernel | 7.8 | September 09, 2026 |
CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Citrix NetScaler ADC and NetScaler Gateway | 9.8 | August 29, 2026 |
CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft SQL Server | 8.8 | August 29, 2026 |
CVE-2026-60004 | Gitea Code Injection Vulnerability | Gitea | 9.8 | August 28, 2026 |
CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | 10.0 | August 27, 2026 |
CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | Synacor Zimbra Collaboration Suite (ZCS) | 8.9 | August 24, 2026 |
CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | TrueConf Server | 9.0 | September 03, 2026 |
CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | TrueConf Server | 9.8 | August 23, 2026 |
CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | MLflow | 9.3 | September 02, 2026 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | Microsoft Internet Key Exchange (IKE) Service Extensions | 9.8 | August 21, 2026 |
CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | Broadcom VMware vCenter | 9.8 | August 21, 2026 |
CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | Microsoft SharePoint | 9.1 | August 21, 2026 |
CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | Apple macOS | 9.8 | August 21, 2026 |
CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | Ray-Project Ray | 8.8 | August 20, 2026 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | Cisco Secure Firewall ASA and Secure Firewall Threat Defense | 8.6 | August 14, 2026 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Microsoft Windows Ancillary Function Driver for WinSock | 7.0 | August 25, 2026 |
CVE-2026-72898 | Metabase SQL Injection Vulnerability | Metabase | 10.0 | August 14, 2026 |
CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | Progress LoadMaster | 9.8 | August 10, 2026 |
CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | JetBrains TeamCity | 9.8 | August 08, 2026 |
CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | N-able N-central | 7.4 | August 07, 2026 |
CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | Apache Tomcat | 7.5 | August 07, 2026 |
CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | IBM Langflow | 9.8 | August 07, 2026 |
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | N-able N-central | 8.1 | August 06, 2026 |
CVEs Details
CVE-2026-82078
All versions of PaperCut NG and PaperCut MF
Affected CPE: cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*, cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
CWE ID: CWE-470 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter, T1070: Indicator Removal
Patch Link: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
CVE-2026-81578
All versions of PaperCut NG and PaperCut MF
Affected CPE: cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*, cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
CWE ID: CWE-306 Associated TTPs: T1190: Exploit Public-Facing Application, T1562: Impair Defenses
Patch Link: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
CVE-2023-49105
ownCloud Server: 10.6.0 - 10.13.0
Affected CPE: cpe:2.3:a:owncloud:core:*:*:*:*:*:*:*:*
CWE ID: CWE-287 Associated TTPs: T1589: Gather Victim Identity Information
Patch Link: https://owncloud.com/download-server
CVE-2026-53362
Linux kernel
Affected CPE: cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE ID: CWE-122, CWE-787 Associated TTPs: T1068: Exploitation for Privilege Escalation
CVE-2026-66384
JFrog Artifactory versions before 7.146.35 and the 7.161.0 through 7.161.16 line
Affected CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
CWE ID: CWE-22 Associated TTPs: T1552: Unsecured Credentials
Patch Link: https://jfrog.com/community/download-artifactory-oss/
CVE-2021-23758
All versions of the ajaxpro.2 package before 21.11.29.1
Associated Actor: UAT-10147
Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter
Affected CPE: cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*, cpe:2.3:a:michaelschwarz:ajax.net_professional:*:*:*:*:*:.net:*:*
CWE ID: CWE-502 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://github.com/michaelschwarz/Ajax.NET-Professional/releases/
CVE-2015-3246
libuser before 0.56.13-8 and 0.60 before 0.60-7
Associated Actor: UAT-10147
Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter
Affected CPE: cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*, cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*, cpe:2.3:a:libuser_project:libuser:*:*:*:*:*:*:*:*
CWE ID: CWE-264, CWE-367 Associated TTPs: T1068: Exploitation for Privilege Escalation
Patch Link: https://pkgs.org/download/libuser
CVE-2015-5287
Automatic Bug Reporting Tool (ABRT) before 2.7.1
Associated Actor: UAT-10147
Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter
Affected CPE: cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:*, cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
CWE ID: CWE-59 Associated TTPs: T1068: Exploitation for Privilege Escalation
Patch Link: https://github.com/abrt/abrt/releases
CVE-2022-0995
Linux Kernel versions through 5.17:rc7
Associated Actor: UAT-10147
Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter
Affected CPE: cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE ID: CWE-787 Associated TTPs: T1499: Endpoint Denial of Service, T1068: Exploitation for Privilege Escalation
CVE-2026-8452
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; NetScaler ADC FIPS before 14.1-72.61 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.272
Affected CPE: cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*, cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*, cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*, cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
CWE ID: CWE-119 Associated TTPs: T1190: Exploit Public-Facing Application, T1203: Exploitation for Client Execution
Patch Link: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
CVE-2019-1068
Multiple Microsoft SQL Server 2014/2016/2017 builds across GDR/CU channels (32-bit and x64-based systems)
Affected CPE: cpe:2.3:a:microsoft:sql_server:*:*:*:*:*:*:*:*
CWE ID: CWE-20 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068
CVE-2026-60004
Gitea (1.17 through 1.27.0, before 1.27.1)
Affected CPE: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*
CWE ID: CWE-94 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://blog.gitea.com/release-of-1.27.1/
CVE-2026-21962
Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); WebLogic Server Proxy Plug-in for Microsoft IIS (12.2.1.4.0)
Affected CPE: cpe:2.3:a:oracle:http_server:*:*:*:*:*:*:*:*, cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:*:*:*:*:*:*:*:*
CWE ID: CWE-284 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://www.oracle.com/security-alerts/cpujan2026.html
CVE-2026-73570
Zimbra Collaboration (ZCS) before 10.1.20
Affected CPE: cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
CWE ID: CWE-78 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20
CVE-2026-72530
TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier
Associated Actor: Head Mare
Associated Attacks/Ransomware: PhantomCore, PhantomGraph
Affected CPE: cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*, cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
CWE ID: CWE-94 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://trueconf.com/products/tcsf/trueconf-server-free.html
CVE-2026-72529
TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier
Associated Actor: Head Mare
Associated Attacks/Ransomware: PhantomCore, PhantomGraph
Affected CPE: cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*, cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
CWE ID: CWE-306 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
Patch Link: https://trueconf.com/products/tcsf/trueconf-server-free.html
CVE-2026-64849
MLflow (Before 3.15.0)
Affected CPE: cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*
CWE ID: CWE-918 Associated TTPs: T1190: Exploit Public-Facing Application, T1552: Unsecured Credentials
Patch Link: https://github.com/mlflow/mlflow/releases/#release-v3.15.1, https://github.com/mlflow/mlflow/releases/tag/v3.15.0
CVE-2026-33824
Windows Server 2016, 2019, 2022, 2025; Windows 10-11 25H2
Associated Actor: knaithe (aka KnYuan)
Affected CPE: cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*, cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*
CWE ID: CWE-415 Associated TTPs: T1190: Exploit Public-Facing Application
Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
CVE-2026-59310
VMware vCenter (9.1.x.x, 9.0.x.x, 8.0, 7.0), VMware Cloud Foundation (9.1.x.x, 9.0.x.x, 5.x), VMware vSphere Foundation (9.1.x.x, 9.0.x.x), VMware Telco Cloud Platform (3.0, 4.x, 5.0.x, 5.1.x), VMware Telco Cloud Infrastructure (3.0)
Associated Attacks/Ransomware: Babuk-derived ESXi ransomware
Affected CPE: cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:vsphere_foundation:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
CWE ID: CWE-22 Associated TTPs: T1190: Exploit Public-Facing Application, T1053: Scheduled Task/Job, T1059: Command and Scripting Interpreter
CVE-2026-55040
Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016
Affected CPE: cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*, cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*, cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
CWE ID: CWE-1390 Associated TTPs: T1190: Exploit Public-Facing Application
Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
CVE-2026-65400
Apple macOS Sonoma (Before 14.8.9), macOS Sequoia (Before 15.7.9), macOS Tahoe (Before 26.6.1)
Associated Attacks/Ransomware: Monero Miner
Affected CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CWE ID: CWE-287 Associated TTPs: T1190: Exploit Public-Facing Application, T1133: External Remote Services, T1496: Resource Hijacking
Patch Link: https://support.apple.com/en-us/148170, https://support.apple.com/en-us/148171, https://support.apple.com/en-us/148172
CVE-2025-62593
Ray Prior to version 2.52.0
Associated Attacks/Ransomware: RondoDox, ShadowRay 2.0
Affected CPE: cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*
CWE ID: CWE-94, CWE-352 Associated TTPs: T1189: Drive-by Compromise, T1059: Command and Scripting Interpreter
Patch Link: https://github.com/ray-project/ray/releases
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software
Affected CPE: cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*, cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*
CWE ID: CWE-244 Associated TTPs: T1190: Exploit Public-Facing Application, T1499: Endpoint Denial of Service
CVE-2026-68820
Windows Server 2012, 2016, 2019, 2022, 2025, Windows 10-11 26H1
Associated Actor: Lazarus
Associated Attacks/Ransomware: Troy, FudModule, RelayShell, MISTPEN, ForestTiger
Affected CPE: cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*, cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
CWE ID: CWE-416 Associated TTPs: T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation
Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
CVE-2026-72898
Metabase both open-source and Enterprise editions versions prior to x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5
Affected CPE: cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*
CWE ID: CWE-89 Associated TTPs: T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation
Patch Link: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
CVE-2026-8037
Kemp LoadMaster: GA v7.2.63.1 and older; LTSF v7.2.54.17 and older
Affected CPE: cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
CWE ID: CWE-77 Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
CVE-2026-63077
JetBrains TeamCity On-Premises (all versions before 2025.11.7 and before 2026.1.3)
Affected CPE: cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
CWE ID: CWE-502 Associated TTPs: T1190: Exploit Public-Facing Application, T1195: Supply Chain Compromise, T1059: Command and Scripting Interpreter
Patch Link: https://www.jetbrains.com/teamcity/download/other/
CVE-2026-18556
N-able N-central (Before 2026.2)
Affected CPE: cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
CWE ID: CWE-288 Associated TTPs: T1190: Exploit Public-Facing Application
Patch Link: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/
CVE-2026-34486
Apache Tomcat: 11.0.20, 10.1.53, 9.0.116
Associated Actor: knaithe (aka KnYuan)
Associated Attacks/Ransomware: SNOWLIGHT
Affected CPE: cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
CWE ID: CWE-311 Associated TTPs: T1190: Exploit Public-Facing Application
Patch Link: https://tomcat.apache.org/index.html
CVE-2026-9198
IBM Langflow OSS 1.0.0 through 1.10.0
Affected CPE: cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
CWE ID: CWE-94 Associated TTPs: T1190: Exploit Public-Facing Application, T1059.006: Command and Scripting Interpreter: Python
Patch Link: https://www.ibm.com/support/pages/node/7278927
CVE-2026-18577
N-able N-central (Before 2026.3.1.7)
Affected CPE: cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
CWE ID: CWE-288 Associated TTPs: T1190: Exploit Public-Facing Application, T1057: Process Discovery
Patch Link: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/
Recommendations
To ensure the security of their systems and data, organizations should prioritize the vulnerabilities listed above and promptly apply patches to them before the due date provided.
It is essential to comply with Binding Operational Directive 26-04 provided by CISA. This directive outlines the minimum cybersecurity standards that all federal agencies must follow to protect their organization from cybersecurity threats.
The affected products listed in the report can help organizations identify assets that have been affected by KEVs, even without conducting a scan. These assets should be patched with priority to reduce the risk.
References
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
