CISA Adds One Known Exploited Vulnerability to Catalog
2026-08-19T19:24:00Z•2be5cc1e17ca156b5a838284064241c6e0fa3fe9591aaaa15890605fbd9bd9bf
CVE-2025-62593CVE-2026-18556CVE-2026-20349CVE-2026-33824CVE-2026-34486CVE-2026-55040CVE-2026-59310CVE-2026-63077CVE-2026-64849CVE-2026-65400CVE-2026-68820CVE-2026-72898CVE-2026-8037CVE-2026-9198Apache TomcatApple macOSCISACisco ASAIBM LangflowJetBrains TeamCityKEVKnown Exploited VulnerabilitiesMLflowMetabaseMicrosoftN-able N-centralProgress LoadMasterRay ProjectVMware vCenterWindowsactive exploitationpatch prioritizationvulnerability management
What happened
CISA reported the addition of 15 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between August 5 and August 19, 2026, based on evidence of active exploitation. Affected products include MLflow, Microsoft IKE and SharePoint, VMware vCenter, Apple macOS, Ray Project, Cisco ASA/FTD, Microsoft Windows, Metabase, Progress LoadMaster, JetBrains TeamCity, IBM Langflow, N-able N-central, and Apache Tomcat. CISA urges rapid remediation, asset exposure assessment, and post-exploitation compromise checks, with mandatory prioritization for applicable U.S. federal civilian agencies.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 2be5cc1e17ca156b5a838284064241c6e0fa3fe9591aaaa15890605fbd9bd9bf
- Enrichment time
- 2026-08-19T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.