CISA Adds One Known Exploited Vulnerability to Catalog

2026-08-19T19:24:00Z2be5cc1e17ca156b5a838284064241c6e0fa3fe9591aaaa15890605fbd9bd9bf
CVE-2025-62593CVE-2026-18556CVE-2026-20349CVE-2026-33824CVE-2026-34486CVE-2026-55040CVE-2026-59310CVE-2026-63077CVE-2026-64849CVE-2026-65400CVE-2026-68820CVE-2026-72898CVE-2026-8037CVE-2026-9198Apache TomcatApple macOSCISACisco ASAIBM LangflowJetBrains TeamCityKEVKnown Exploited VulnerabilitiesMLflowMetabaseMicrosoftN-able N-centralProgress LoadMasterRay ProjectVMware vCenterWindowsactive exploitationpatch prioritizationvulnerability management

What happened

CISA reported the addition of 15 vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between August 5 and August 19, 2026, based on evidence of active exploitation. Affected products include MLflow, Microsoft IKE and SharePoint, VMware vCenter, Apple macOS, Ray Project, Cisco ASA/FTD, Microsoft Windows, Metabase, Progress LoadMaster, JetBrains TeamCity, IBM Langflow, N-able N-central, and Apache Tomcat. CISA urges rapid remediation, asset exposure assessment, and post-exploitation compromise checks, with mandatory prioritization for applicable U.S. federal civilian agencies.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
2be5cc1e17ca156b5a838284064241c6e0fa3fe9591aaaa15890605fbd9bd9bf
Enrichment time
2026-08-19T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.