CISA added 9 vulnerabilities to the Known Exploited Vulnerabilities catalog between 17 and 23 August 2026, across five separate batches. Seven of the nine carry CVSS scores of 9.0 or above, all nine have confirmed in-the-wild exploitation, and one, the Microsoft SharePoint flaw CVE-2026-55040, was exploited within days of a public proof of concept. Patch VMware vCenter CVE-2026-59310 first: a suspected China-nexus actor has already used it to compromise 361 victim IP addresses across 47 countries and deploy Babuk-derived ransomware on ESXi hosts. The week’s pattern is exploitation of the management plane: vCenter, SharePoint, a video conferencing server, an ML platform, and macOS Screen Sharing are all systems that administer or aggregate other systems. EPSS scores are not available this week; the enrichment source could not be reached, and no score is guessed.
Which vulnerabilities should you patch first this week?
Patch this first because exploitation is not theoretical: incident response firm QUIRSO documented 361 compromised victim IPs in 47 countries, with a suspected China-nexus actor chaining the vCenter syslog path traversal into root backdoors, persistent SSH access, and Babuk-derived ransomware on ESXi. CVSS 9.8, added to CISA KEV on 18 August 2026. Update to vCenter 8.0 U3k, 9.0.2.0100, or 9.1.0.0300 now, and treat any unpatched, internet-reachable vCenter as potentially compromised rather than merely vulnerable.
This is an unauthenticated remote code execution path on an internet-facing mail platform: crafted SMTP requests reach the optional zimbra-snmp notification handler and execute OS commands as the zimbra user. CERT Polska reported active exploitation and CISA added it to KEV on 21 August 2026 with a federal due date of 24 August. CVSS 8.9, but external reachability and no-auth exploitation outrank the score; upgrade to Zimbra 10.1.20 or disable the zimbra-snmp package.
Attackers began exploiting this authentication bypass within days of a public proof of concept, and CISA added it to KEV on 18 August 2026. CVSS 9.1, patched since 14 July 2026, which means every exploited server this week was running a month-old known gap. Apply the July 2026 SharePoint security updates and hunt for bypass activity dating back to the PoC release.
CVE-2026-59310: VMware vCenter Server directory traversal
What it is: CVE-2026-59310 is a directory traversal vulnerability in the VMware vCenter Server syslog component that lets an attacker with network access to vCenter execute arbitrary code, no user interaction required.
Affected products and versions: VMware vCenter Server 8.0 through 8.0 U3k (fixed in 8.0 U3k), 9.0.x before 9.0.2.0100, and 9.1.x before 9.1.0.0300, plus VMware Cloud Foundation 5.x and 9.x, vSphere Foundation 9.x, and Telco Cloud Infrastructure and Platform lines, per Broadcom advisory VMSA-2026-0006.
Severity: CVSS 9.8 Critical (assigned by VMware/Broadcom as CNA). EPSS not available.
Exploitation status: Confirmed in the wild. Added to CISA KEV on 18 August 2026, federal remediation due 21 August 2026. QUIRSO researchers documented exploitation beginning 3 August 2026, five days after disclosure, reaching 361 victim IPs in 47 countries, with the heaviest concentrations in Germany (55), the US (41), and Turkey (38).
Patch status: Fixed in vCenter 8.0 U3k, 9.0.2.0100, and 9.1.0.0300, released with Broadcom advisory VMSA-2026-0006 on 29 July 2026.
What to do: Update every vCenter instance to 8.0 U3k, 9.0.2.0100, or 9.1.0.0300. Remove vCenter from direct internet exposure and restrict management-plane access to a dedicated network. On any host that was unpatched after 3 August, hunt for the campaign’s artifacts: malformed cron files, a “linuxFile” backdoor, and unauthorized accounts named adminuser, vcadmin, or vcenter_admin.
CVE-2026-33824: Microsoft Windows IKE Extension double free
What it is: CVE-2026-33824 is a double free memory corruption flaw in the Windows Internet Key Exchange (IKE) Extension that allows an unauthorized attacker to execute code over the network without authentication or user interaction.
Affected products and versions: Windows 10 versions 1607 through 22H2, Windows 11 versions 22H3 through 26H1, and Windows Server 2016 and later, across x64, 32-bit, and ARM64 builds; patched thresholds vary by build per the Microsoft Security Update Guide.
Severity: CVSS 9.8 Critical (assigned by Microsoft). EPSS not available.
Exploitation status: Confirmed in the wild. Added to CISA KEV on 18 August 2026, federal remediation due 21 August 2026. The Hacker News reports exploitation by Chinese-speaking threat actors, four months after the patch shipped.
Patch status: Fixed in Microsoft’s April 2026 security updates, released 14 April 2026.
What to do: Confirm the April 2026 cumulative update is actually installed on every system running the IKE service, including servers behind load balancers that patch reporting often misses. Block UDP 500 and 4500 from untrusted networks where IKE VPN termination is not required.
CVE-2026-73570: Zimbra Collaboration OS command injection
What it is: CVE-2026-73570 is an OS command injection flaw in Zimbra Collaboration’s SNMP notification processing that lets an unauthenticated attacker execute arbitrary commands as the zimbra user by sending crafted SMTP requests.
Affected products and versions: Zimbra Collaboration (ZCS) versions before 10.1.20, and only where the optional zimbra-snmp package is installed with SNMP notifications enabled.
Severity: CVSS 8.9 High (CNA assessment published on NVD). EPSS not available.
Exploitation status: Confirmed in the wild. CERT Polska reported active exploitation, and CISA added CVE-2026-73570 to KEV on 21 August 2026 with a federal remediation due date of 24 August 2026.
Patch status: Fixed in Zimbra Collaboration 10.1.20, released July 2026.
What to do: Upgrade to Zimbra 10.1.20, or remove the zimbra-snmp package where it is not required. Then hunt: CERT Polska recommends reviewing /var/log/zimbra.log for suspicious service restarts and checking for files created in the last 30 days in Zimbra’s writable directories.
CVE-2026-55040: Microsoft SharePoint Server authentication bypass
What it is: CVE-2026-55040 is a weak authentication flaw in Microsoft SharePoint Server that lets an unauthorized attacker bypass a security feature over the network without credentials.
Affected products and versions: SharePoint Server 2016 before build 16.0.5561.1001, SharePoint Server 2019 before 16.0.10417.20175, and SharePoint Server Subscription Edition before 16.0.19725.20434. SharePoint Online is not listed as affected.
Severity: CVSS 9.1 Critical (assigned by Microsoft). EPSS not available.
Exploitation status: Confirmed in the wild, with attacks beginning days after a public proof of concept was released in mid August. Added to CISA KEV on 18 August 2026, federal remediation due 21 August 2026.
Patch status: Fixed in Microsoft’s July 2026 security updates for SharePoint, released 14 July 2026.
What to do: Apply the July 2026 SharePoint updates and verify the build numbers above on every farm. Review authentication logs back to early August for anomalous access that skipped expected authentication steps, since the PoC predates the KEV entry.
CVE-2026-64849: MLflow server-side request forgery
What it is: CVE-2026-64849 is a server-side request forgery flaw in MLflow’s unauthenticated webhook test endpoint: URL validation is applied only to the original URL, so a redirect lets an attacker reach internal and cloud metadata services and read the response back.
Affected products and versions: MLflow versions before 3.15.0.
Severity: CVSS 9.3 Critical (assigned by GitHub as CNA). EPSS not available.
Exploitation status: Confirmed in the wild. watchTowr and VulnCheck documented malicious scanning within hours of the CVE assignment on 17 August 2026, with attackers using the flaw to pull cloud credentials and secrets from metadata endpoints. Added to CISA KEV on 19 August 2026, federal remediation due 2 September 2026.
Patch status: Fixed in MLflow 3.15.0.
What to do: Upgrade MLflow to 3.15.0 on every tracking server. Take MLflow tracking servers off the public internet, and rotate any cloud credentials reachable from the instance metadata service of exposed hosts, since exfiltration leaves little trace on the MLflow side.
New hacking technique: Cryptographic Context Injection against AI assistants
What researchers demonstrated: Adversa AI researcher Rony Utevsky published Cryptographic Context Injection on 20 August 2026, a zero-click technique that smuggles encrypted malicious instructions past AI content filters and exfiltrates a user’s private chat data from xAI’s Grok.
How it works:
- The attacker plants ciphertext, encrypted with AES-256-GCM using a PBKDF2-derived key, in an ordinary webpage.
- A user asks the AI assistant to summarize the page; content classifiers cannot inspect the encrypted payload, so it passes filtering.
- The page’s visible text nudges the assistant to run decryption code in its own Python runtime, recovering the hidden instructions.
- The decrypted payload directs the assistant to build URLs embedding the user’s name, location, subscription tier, and chat history.
- The assistant’s built-in browsing tools navigate to attacker-controlled servers, delivering the data.
What to do: Inventory which AI assistants in your environment combine code execution, web browsing, and access to user context, since that trio is the vulnerable architecture. Restrict agent browsing to allowlisted destinations where business use permits. Treat assistant-accessible chat history as sensitive data with the same exposure review you would apply to a web application session store.
CISA KEV additions, 17 to 23 Aug 2026
CISA added 9 vulnerabilities to the KEV catalog this week, in batches on 17, 18, 19, 20, and 21 August 2026; no additions were published on 22 or 23 August.
| CVE | Product | CVSS | Date added to KEV | Federal due date |
|---|---|---|---|---|
| CVE-2025-62593 | Ray (AI compute framework) | 8.8 (v3.1, NIST; 9.4 v4.0 per GitHub CNA) | 17 Aug 2026 | 20 Aug 2026 |
| CVE-2026-65400 | Apple macOS Screen Sharing | 9.8 | 18 Aug 2026 | 21 Aug 2026 |
| CVE-2026-55040 | Microsoft SharePoint Server | 9.1 | 18 Aug 2026 | 21 Aug 2026 |
| CVE-2026-59310 | VMware vCenter Server | 9.8 | 18 Aug 2026 | 21 Aug 2026 |
| CVE-2026-33824 | Microsoft Windows IKE Extension | 9.8 | 18 Aug 2026 | 21 Aug 2026 |
| CVE-2026-64849 | MLflow | 9.3 | 19 Aug 2026 | 2 Sep 2026 |
| CVE-2026-72529 | TrueConf Server | 9.8 | 20 Aug 2026 | See KEV entry |
| CVE-2026-72530 | TrueConf Server | 9.0 | 20 Aug 2026 | See KEV entry |
| CVE-2026-73570 | Zimbra Collaboration | 8.9 | 21 Aug 2026 | 24 Aug 2026 |
The two TrueConf Server flaws, exploited by the Head Mare group via port 4307/TCP to plant web shells and distribute trojanized client installers, are fixed in versions 5.3.9, 5.4.9, and 5.5.5. The macOS Screen Sharing flaw CVE-2026-65400, fixed in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, was exploited to deploy Monero cryptominers. Ray CVE-2025-62593 carries a scoring conflict worth noting: NIST assigns CVSS 3.1 8.8 while the GitHub CNA assigns CVSS 4.0 9.4.
Related reading
- The Great AI Divide in cybersecurity, because this week’s Ray, MLflow, and Cryptographic Context Injection items all sit on the AI attack surface that divide describes.
- Belief state engines and autonomous security under uncertainty, for the research view on agentic systems making security decisions, the same architecture the week’s technique item abuses.
How FireCompass helps
Every one of this week’s nine KEV entries is an internet-reachable service, and the practical question for a security team is not “is the CVE critical” but “do we run an affected version on an asset an attacker can reach, and is it exploitable there”. FireCompass answers that question the way an attacker would: its agentic AI platform discovers your external surface, fingerprints what is running, and executes real exploit validation with proof, so the vCenter or SharePoint finding you escalate is confirmed exploitable rather than version-matched. Findings carry a false positive rate of under 2 percent, against 40 to 70 percent for scanners, and the cadence matters as much as the accuracy: CVEs are exploited in about 3 days, which is faster than most quarterly scan cycles even begin.
Ready to find out which of your internet-facing assets an attacker could actually reach this week?
Frequently asked questions
Which CVEs were actively exploited this week (17 to 23 Aug 2026)?
All nine CISA KEV additions this week have confirmed exploitation: VMware vCenter CVE-2026-59310, Windows IKE CVE-2026-33824, SharePoint CVE-2026-55040, macOS CVE-2026-65400, MLflow CVE-2026-64849, Zimbra CVE-2026-73570, TrueConf CVE-2026-72529 and CVE-2026-72530, and Ray CVE-2025-62593, added between 17 and 21 August 2026.
What is the most critical CVE this week?
CVE-2026-59310 in VMware vCenter, CVSS 9.8. It is not just exploitable but exploited at scale: 361 victim IPs across 47 countries were compromised in a campaign that chained it into root backdoors and Babuk-derived ransomware on ESXi hosts. Fixed versions are 8.0 U3k, 9.0.2.0100, and 9.1.0.0300.
Is CVE-2026-59310 being exploited?
Yes. CISA added it to the KEV catalog on 18 August 2026, and QUIRSO researchers documented exploitation from 3 August 2026, five days after disclosure, by a suspected China-nexus actor. Compromise indicators include cron-based persistence, a “linuxFile” backdoor, and rogue accounts named adminuser, vcadmin, and vcenter_admin.
How do I fix CVE-2026-73570 in Zimbra?
Upgrade Zimbra Collaboration to 10.1.20, which fixes the flaw, or remove the optional zimbra-snmp package if you do not need it. Then check /var/log/zimbra.log for suspicious service restarts and hunt for files created in the last 30 days, per CERT Polska’s guidance. CISA’s federal due date was 24 August 2026.
How many vulnerabilities did CISA add to KEV this week?
Nine, between 17 and 23 August 2026, in five batches: Ray on 17 August, then macOS, SharePoint, vCenter, and Windows IKE on 18 August, MLflow on 19 August, two TrueConf Server flaws on 20 August, and Zimbra on 21 August. Seven of the nine carry CVSS scores of 9.0 or above.
Is there a public exploit for CVE-2026-55040?
Yes. A public proof of concept for the SharePoint authentication bypass was released in mid August 2026, and attackers began exploiting it within days, which drove the 18 August KEV addition. The fix has been available since 14 July 2026 in the July SharePoint security updates.
How should I prioritize patching when everything is CVSS 9?
Rank on exploitation first, reachability second, score third. A CVSS 8.9 flaw under active exploitation on an internet-facing mail server, like this week’s Zimbra entry, outranks a higher-scored bug with no exploitation. This week that logic puts vCenter (361 confirmed victims), Zimbra (unauthenticated, internet-facing), and SharePoint (public PoC) ahead of the rest.
