CISA Known Exploited Vulnerability Catalog August 2026

CISA KEV
Download Now
CISA Known Exploited Vulnerabilities Catalog — August 2026 | HiveForce Labs

Summary

The Known Exploited Vulnerability (KEV) catalog, maintained by CISA, is the authoritative source of vulnerabilities that have been exploited in the wild. It is recommended that all organizations review and monitor the KEV catalog, prioritize remediation of listed vulnerabilities, and reduce the likelihood of compromise by threat actors. In August 2026, 31 vulnerabilities met the criteria for inclusion in CISA’s KEV catalog. Of these, 4 are zero-day vulnerabilities; 12 have been exploited by a threat actor and employed in attacks.


CVEs List

CVE IDNameAffected ProductCVSS 3.xDue Date
CVE-2026-82078PaperCut NG/MF Unsafe Reflection VulnerabilityPaperCut NG/MF9.1September 14, 2026
CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function VulnerabilityPaperCut NG/MF9.8September 14, 2026
CVE-2023-49105ownCloud Improper Authentication VulnerabilityownCloud9.8August 30, 2026
CVE-2026-53362Linux Kernel Unspecified VulnerabilityLinux Kernel7.8August 30, 2026
CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory VulnerabilityJFrog Artifactory5.3September 10, 2026
CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityAjax.NET Professional9.8September 09, 2026
CVE-2015-3246Red Hat Libuser Race Condition VulnerabilityRed Hat Libuser5.1September 09, 2026
CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityRed Hat Automatic Bug Reporting Tool7.8September 09, 2026
CVE-2022-0995Linux Kernel Out-of-Bounds Write VulnerabilityLinux Kernel7.8September 09, 2026
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrix NetScaler ADC and NetScaler Gateway9.8August 29, 2026
CVE-2019-1068Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server8.8August 29, 2026
CVE-2026-60004Gitea Code Injection VulnerabilityGitea9.8August 28, 2026
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in10.0August 27, 2026
CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection VulnerabilitySynacor Zimbra Collaboration Suite (ZCS)8.9August 24, 2026
CVE-2026-72530TrueConf Server Code Injection VulnerabilityTrueConf Server9.0September 03, 2026
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function VulnerabilityTrueConf Server9.8August 23, 2026
CVE-2026-64849MLflow Server-Side Request Forgery VulnerabilityMLflow9.3September 02, 2026
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoft Internet Key Exchange (IKE) Service Extensions9.8August 21, 2026
CVE-2026-59310Broadcom VMware vCenter Path Traversal VulnerabilityBroadcom VMware vCenter9.8August 21, 2026
CVE-2026-55040Microsoft SharePoint Weak Authentication VulnerabilityMicrosoft SharePoint9.1August 21, 2026
CVE-2026-65400Apple macOS Improper Authentication VulnerabilityApple macOS9.8August 21, 2026
CVE-2025-62593Ray-Project Ray Code Injection VulnerabilityRay-Project Ray8.8August 20, 2026
CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection VulnerabilityCisco Secure Firewall ASA and Secure Firewall Threat Defense8.6August 14, 2026
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityMicrosoft Windows Ancillary Function Driver for WinSock7.0August 25, 2026
CVE-2026-72898Metabase SQL Injection VulnerabilityMetabase10.0August 14, 2026
CVE-2026-8037Progress LoadMaster Command Injection VulnerabilityProgress LoadMaster9.8August 10, 2026
CVE-2026-63077JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityJetBrains TeamCity9.8August 08, 2026
CVE-2026-18556N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityN-able N-central7.4August 07, 2026
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityApache Tomcat7.5August 07, 2026
CVE-2026-9198IBM Langflow Code Injection VulnerabilityIBM Langflow9.8August 07, 2026
CVE-2026-18577N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityN-able N-central8.1August 06, 2026

CVEs Details

CVE-2026-82078

All versions of PaperCut NG and PaperCut MF

Affected CPE: cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*, cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*

CWE ID: CWE-470   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter, T1070: Indicator Removal

Patch Link: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

CVE-2026-81578

All versions of PaperCut NG and PaperCut MF

Affected CPE: cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*, cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*

CWE ID: CWE-306   Associated TTPs: T1190: Exploit Public-Facing Application, T1562: Impair Defenses

Patch Link: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

CVE-2023-49105

ownCloud Server: 10.6.0 - 10.13.0

Affected CPE: cpe:2.3:a:owncloud:core:*:*:*:*:*:*:*:*

CWE ID: CWE-287   Associated TTPs: T1589: Gather Victim Identity Information

Patch Link: https://owncloud.com/download-server

CVE-2026-53362

Linux kernel

Affected CPE: cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CWE ID: CWE-122, CWE-787   Associated TTPs: T1068: Exploitation for Privilege Escalation

Patch Link: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e9eacf19281ea2498b36291b56c9606118c2d74e

CVE-2026-66384

JFrog Artifactory versions before 7.146.35 and the 7.161.0 through 7.161.16 line

Affected CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*

CWE ID: CWE-22   Associated TTPs: T1552: Unsecured Credentials

Patch Link: https://jfrog.com/community/download-artifactory-oss/

CVE-2021-23758

All versions of the ajaxpro.2 package before 21.11.29.1

Associated Actor: UAT-10147

Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter

Affected CPE: cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*, cpe:2.3:a:michaelschwarz:ajax.net_professional:*:*:*:*:*:.net:*:*

CWE ID: CWE-502   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://github.com/michaelschwarz/Ajax.NET-Professional/releases/

CVE-2015-3246

libuser before 0.56.13-8 and 0.60 before 0.60-7

Associated Actor: UAT-10147

Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter

Affected CPE: cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*, cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*, cpe:2.3:a:libuser_project:libuser:*:*:*:*:*:*:*:*

CWE ID: CWE-264, CWE-367   Associated TTPs: T1068: Exploitation for Privilege Escalation

Patch Link: https://pkgs.org/download/libuser

CVE-2015-5287

Automatic Bug Reporting Tool (ABRT) before 2.7.1

Associated Actor: UAT-10147

Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter

Affected CPE: cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:*, cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*

CWE ID: CWE-59   Associated TTPs: T1068: Exploitation for Privilege Escalation

Patch Link: https://github.com/abrt/abrt/releases

CVE-2022-0995

Linux Kernel versions through 5.17:rc7

Associated Actor: UAT-10147

Associated Attacks/Ransomware: NoodleRAT, SPECTRE, Meterpreter

Affected CPE: cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CWE ID: CWE-787   Associated TTPs: T1499: Endpoint Denial of Service, T1068: Exploitation for Privilege Escalation

Patch Link: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb

CVE-2026-8452

NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; NetScaler ADC FIPS before 14.1-72.61 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.272

Affected CPE: cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*, cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*, cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*, cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

CWE ID: CWE-119   Associated TTPs: T1190: Exploit Public-Facing Application, T1203: Exploitation for Client Execution

Patch Link: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

CVE-2019-1068

Multiple Microsoft SQL Server 2014/2016/2017 builds across GDR/CU channels (32-bit and x64-based systems)

Affected CPE: cpe:2.3:a:microsoft:sql_server:*:*:*:*:*:*:*:*

CWE ID: CWE-20   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068

CVE-2026-60004

Gitea (1.17 through 1.27.0, before 1.27.1)

Affected CPE: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*

CWE ID: CWE-94   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://blog.gitea.com/release-of-1.27.1/

CVE-2026-21962

Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); WebLogic Server Proxy Plug-in for Microsoft IIS (12.2.1.4.0)

Affected CPE: cpe:2.3:a:oracle:http_server:*:*:*:*:*:*:*:*, cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:*:*:*:*:*:*:*:*

CWE ID: CWE-284   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://www.oracle.com/security-alerts/cpujan2026.html

CVE-2026-73570

Zimbra Collaboration (ZCS) before 10.1.20

Affected CPE: cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

CWE ID: CWE-78   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20

CVE-2026-72530

TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier

Associated Actor: Head Mare

Associated Attacks/Ransomware: PhantomCore, PhantomGraph

Affected CPE: cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*, cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*

CWE ID: CWE-94   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://trueconf.com/products/tcsf/trueconf-server-free.html

CVE-2026-72529

TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier

Associated Actor: Head Mare

Associated Attacks/Ransomware: PhantomCore, PhantomGraph

Affected CPE: cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*, cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*

CWE ID: CWE-306   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://trueconf.com/products/tcsf/trueconf-server-free.html

CVE-2026-64849

MLflow (Before 3.15.0)

Affected CPE: cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*

CWE ID: CWE-918   Associated TTPs: T1190: Exploit Public-Facing Application, T1552: Unsecured Credentials

Patch Link: https://github.com/mlflow/mlflow/releases/#release-v3.15.1, https://github.com/mlflow/mlflow/releases/tag/v3.15.0

CVE-2026-33824

Windows Server 2016, 2019, 2022, 2025; Windows 10-11 25H2

Associated Actor: knaithe (aka KnYuan)

Affected CPE: cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*, cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*

CWE ID: CWE-415   Associated TTPs: T1190: Exploit Public-Facing Application

Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824

CVE-2026-59310

VMware vCenter (9.1.x.x, 9.0.x.x, 8.0, 7.0), VMware Cloud Foundation (9.1.x.x, 9.0.x.x, 5.x), VMware vSphere Foundation (9.1.x.x, 9.0.x.x), VMware Telco Cloud Platform (3.0, 4.x, 5.0.x, 5.1.x), VMware Telco Cloud Infrastructure (3.0)

Associated Attacks/Ransomware: Babuk-derived ESXi ransomware

Affected CPE: cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:vsphere_foundation:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*, cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*

CWE ID: CWE-22   Associated TTPs: T1190: Exploit Public-Facing Application, T1053: Scheduled Task/Job, T1059: Command and Scripting Interpreter

Patch Link: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

CVE-2026-55040

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016

Affected CPE: cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*, cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*, cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

CWE ID: CWE-1390   Associated TTPs: T1190: Exploit Public-Facing Application

Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

CVE-2026-65400

Apple macOS Sonoma (Before 14.8.9), macOS Sequoia (Before 15.7.9), macOS Tahoe (Before 26.6.1)

Associated Attacks/Ransomware: Monero Miner

Affected CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

CWE ID: CWE-287   Associated TTPs: T1190: Exploit Public-Facing Application, T1133: External Remote Services, T1496: Resource Hijacking

Patch Link: https://support.apple.com/en-us/148170, https://support.apple.com/en-us/148171, https://support.apple.com/en-us/148172

CVE-2025-62593

Ray Prior to version 2.52.0

Associated Attacks/Ransomware: RondoDox, ShadowRay 2.0

Affected CPE: cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*

CWE ID: CWE-94, CWE-352   Associated TTPs: T1189: Drive-by Compromise, T1059: Command and Scripting Interpreter

Patch Link: https://github.com/ray-project/ray/releases

CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software

Affected CPE: cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*, cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*

CWE ID: CWE-244   Associated TTPs: T1190: Exploit Public-Facing Application, T1499: Endpoint Denial of Service

Patch Link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

CVE-2026-68820

Windows Server 2012, 2016, 2019, 2022, 2025, Windows 10-11 26H1

Associated Actor: Lazarus

Associated Attacks/Ransomware: Troy, FudModule, RelayShell, MISTPEN, ForestTiger

Affected CPE: cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*, cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*

CWE ID: CWE-416   Associated TTPs: T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation

Patch Link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820

CVE-2026-72898

Metabase both open-source and Enterprise editions versions prior to x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5

Affected CPE: cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*

CWE ID: CWE-89   Associated TTPs: T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation

Patch Link: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf

CVE-2026-8037

Kemp LoadMaster: GA v7.2.63.1 and older; LTSF v7.2.54.17 and older

Affected CPE: cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*, cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*

CWE ID: CWE-77   Associated TTPs: T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter

Patch Link: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691

CVE-2026-63077

JetBrains TeamCity On-Premises (all versions before 2025.11.7 and before 2026.1.3)

Affected CPE: cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

CWE ID: CWE-502   Associated TTPs: T1190: Exploit Public-Facing Application, T1195: Supply Chain Compromise, T1059: Command and Scripting Interpreter

Patch Link: https://www.jetbrains.com/teamcity/download/other/

CVE-2026-18556

N-able N-central (Before 2026.2)

Affected CPE: cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

CWE ID: CWE-288   Associated TTPs: T1190: Exploit Public-Facing Application

Patch Link: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/

CVE-2026-34486

Apache Tomcat: 11.0.20, 10.1.53, 9.0.116

Associated Actor: knaithe (aka KnYuan)

Associated Attacks/Ransomware: SNOWLIGHT

Affected CPE: cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CWE ID: CWE-311   Associated TTPs: T1190: Exploit Public-Facing Application

Patch Link: https://tomcat.apache.org/index.html

CVE-2026-9198

IBM Langflow OSS 1.0.0 through 1.10.0

Affected CPE: cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

CWE ID: CWE-94   Associated TTPs: T1190: Exploit Public-Facing Application, T1059.006: Command and Scripting Interpreter: Python

Patch Link: https://www.ibm.com/support/pages/node/7278927

CVE-2026-18577

N-able N-central (Before 2026.3.1.7)

Affected CPE: cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

CWE ID: CWE-288   Associated TTPs: T1190: Exploit Public-Facing Application, T1057: Process Discovery

Patch Link: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/


Recommendations

01
Prioritize Patching by Due Date

To ensure the security of their systems and data, organizations should prioritize the vulnerabilities listed above and promptly apply patches to them before the due date provided.

02
Comply with Binding Operational Directive 26-04

It is essential to comply with Binding Operational Directive 26-04 provided by CISA. This directive outlines the minimum cybersecurity standards that all federal agencies must follow to protect their organization from cybersecurity threats.

03
Identify Assets from the Affected Products List

The affected products listed in the report can help organizations identify assets that have been affected by KEVs, even without conducting a scan. These assets should be patched with priority to reduce the risk.


References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.