CISA KEV August 18: Windows IKE CVE-2026-33824 unauthenticated network RCE and SharePoint CVE-2026-55040 authentication bypass confirmed exploited, federal deadline tomorrow      MLflow CVE-2026-64849: unauthenticated SSRF in AI platform steals cloud credentials from metadata endpoints, under active scanning and exploitation as of August 18      FUXA CVE-2026-25895: CVSS 9.5 unauthenticated file write in SCADA/HMI software, active scanning for 60 exposed OT deployments begins today      Oracle August CPU: 1,000+ vulnerabilities patched across two dozen products, anchored by CVE-2026-60702 CVSS 9.9 WebLogic Server remote takeover      CISA KEV August 18: Windows IKE CVE-2026-33824 unauthenticated network RCE and SharePoint CVE-2026-55040 authentication bypass confirmed exploited, federal deadline tomorrow      MLflow CVE-2026-64849: unauthenticated SSRF in AI platform steals cloud credentials from metadata endpoints, under active scanning and exploitation as of August 18      FUXA CVE-2026-25895: CVSS 9.5 unauthenticated file write in SCADA/HMI software, active scanning for 60 exposed OT deployments begins today      Oracle August CPU: 1,000+ vulnerabilities patched across two dozen products, anchored by CVE-2026-60702 CVSS 9.9 WebLogic Server remote takeover     
CyberSipTM
Intelligence without the noise
Issue No. 112
August 19, 2026
3 items · past 24h
<5 min read
Today's picture

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18 with a federal deadline of August 21, two of which had not previously been confirmed exploited: CVE-2026-33824, an unauthenticated double-free in Windows IKE Service Extensions that allows remote code execution over the network on any Windows system with IKE enabled, and CVE-2026-55040, a weak authentication bypass in Microsoft SharePoint that lets an unauthenticated attacker circumvent a security feature over the network. Researchers at watchTowr and VulnCheck confirmed active scanning and exploitation of two AI and OT platforms: MLflow CVE-2026-64849, a CVSS 9.3 unauthenticated SSRF in the webhook test endpoint that reaches cloud metadata services to extract credentials and secrets from AI pipelines, and FUXA CVE-2026-25895, a CVSS 9.5 missing authentication and path traversal flaw in SCADA/HMI software that lets an unauthenticated remote attacker write arbitrary files to the server and achieve remote code execution on industrial control systems. Oracle released its August 2026 Critical Patch Update today covering more than 1,000 vulnerabilities across two dozen products including a CVSS 9.9 remote takeover flaw in WebLogic Server.

Today's intelligence
3 items
01 CriticalCISA KEVWindows IKE + SharePoint
Windows IKE and SharePoint are both confirmed actively exploited, with a federal remediation deadline of tomorrow
Both CVEs were in August Patch Tuesday seven days ago without confirmed exploitation flags. CISA added both to KEV on August 18 with a deadline of August 21. CVE-2026-33824 is an unauthenticated network RCE. CVE-2026-55040 is an authentication bypass. If August Patch Tuesday has not fully applied in your environment, these two should move to the front of the queue today.
Lead CVECVE-2026-33824
CVSS 9.8
IKE double free
Unauth network RCE
Second CVECVE-2026-55040
CVSS 9.1
SharePoint weak auth
Unauth bypass
KEV addedAugust 18, 2026
Fed deadlineAugust 21, 2026
(tomorrow)
Patch sourceAugust 2026
Patch Tuesday
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, 2026, setting a federal remediation deadline of August 21 under Binding Operational Directive 26-04. Two of the four were already in Still Watching from prior CyberSip issues: CVE-2026-59310 in VMware vCenter, covered since Issue 97, and CVE-2026-65400 in Apple macOS Screen Sharing, covered since Issue 109. The two that had not previously appeared as confirmed exploited in this brief are new urgency items today. CVE-2026-33824 is a double-free memory corruption vulnerability in the Windows Internet Key Exchange Service Extensions component. The IKE service handles IPsec key negotiation for VPN connections and is enabled by default on Windows systems that use IPsec or L2TP VPN configurations. An unauthenticated remote attacker can send specially crafted network packets to trigger the double-free, corrupting memory in a way that allows arbitrary code execution with the privileges of the affected service. The flaw is scored CVSS 9.8. No credentials and no user interaction are required. Blocking UDP ports 500 and 4500 at the network perimeter reduces exposure from external sources but does not protect against lateral movement within the network from an attacker who has already established a foothold. The patch is in the August 2026 Patch Tuesday release. CVE-2026-55040 is a weak authentication vulnerability in Microsoft Office SharePoint. An unauthenticated remote attacker can exploit the flaw to bypass a security feature over the network. SharePoint is used as a document management, intranet, and collaboration platform in most large enterprises, and authentication bypass at the network layer has historically been the entry point for data exfiltration campaigns targeting SharePoint content. The CVSS score is 9.1. No credentials and no user interaction are required. The patch is also in the August 2026 Patch Tuesday release. CISA confirmed that both are being exploited in the wild as of the August 18 addition date.
Both CVEs were patched in August Patch Tuesday on August 12. At that time, neither carried a confirmed exploitation flag. The seven-day gap between patch release and CISA KEV addition is consistent with the pattern this brief has documented throughout 2026: Patch Tuesday addresses a set of vulnerabilities, some of which are already being exploited by the time the patch releases and some of which begin to see exploitation in the days that follow. Organizations that prioritized the August 12 Patch Tuesday deployment based on the flags available at patch time, specifically the confirmed exploitation of CVE-2026-68820 and the wormable character of CVE-2026-62815, now have two additional confirmed exploited vulnerabilities from the same batch that require immediate attention if the August 12 patches have not fully propagated through the environment. The IKE flaw is the higher priority: unauthenticated network code execution with CVSS 9.8 is in the category where a single unpatched internet-facing Windows system represents a direct exploitation path.
The August 18 KEV batch also added CVE-2026-59310 (vCenter) and CVE-2026-65400 (macOS Screen Sharing), both previously covered. The vCenter addition formalizes what QUIRSO's incident response engagement already confirmed: 361 victims in 47 countries. The macOS addition formalizes what the Dutch NCSC confirmed on August 14. Neither addition changes the recommended actions from Issues 107 and 109. The operationally new items are IKE and SharePoint. For organizations tracking patch compliance through CISA KEV status rather than Patch Tuesday date, today's additions move both CVEs into the category requiring immediate verification that the August 12 patches have applied and the system has been restarted to activate them.
  • Verify that the August 2026 Patch Tuesday update has fully applied and that affected systems have been restarted. Windows security patches require a restart to take effect, and enterprise deployment tools may show patches as installed before the required restart has occurred. Confirm the restart status for any Windows system running IKE or SharePoint.
  • For internet-facing Windows systems where the August 12 patch has not yet applied, block UDP ports 500 and 4500 at the network perimeter as an immediate temporary measure against CVE-2026-33824. This reduces exposure to external attackers but does not protect against lateral movement from a compromised internal host. Patch remains the required remediation.
  • Review SharePoint access logs from August 12 onward for authentication bypass indicators: successful access to SharePoint content from accounts or IP addresses that would not normally reach the affected security control, particularly involving document libraries or lists that contain sensitive content. An authentication bypass may not produce standard failed-login events before successful access occurs.
Both were in Patch Tuesday a week ago without exploitation flags. Both are confirmed exploited today. The deadline is tomorrow. If the August 12 patches are not fully applied and restarted in your environment, IKE and SharePoint are the two items that need to be resolved before August 21.
02 HighMLflow + FUXAAI & OT Exploitation
Attackers are actively exploiting an MLflow SSRF to steal cloud credentials from AI pipelines and scanning a FUXA SCADA flaw for arbitrary file writes on OT systems
MLflow CVE-2026-64849 and FUXA CVE-2026-25895 both became actively targeted within 24 hours of CVE assignment. One steals the cloud credentials and secrets from AI training and serving infrastructure. The other writes arbitrary files to industrial control systems with no authentication. Both are patched. Neither is on CISA KEV yet. Both warrant immediate action.
MLflow CVECVE-2026-64849
CVSS 9.3 SSRF
Fixed in 3.15.0
FUXA CVECVE-2026-25895
CVSS 9.5 file write
Patch available
MLflow statusActive exploitation
confirmed watchTowr
FUXA statusActive scanning
~60 exposed targets
VulnCheck
WatchTowr and VulnCheck published independent analyses on August 18 of active exploitation activity targeting two recently disclosed vulnerabilities in platforms at opposite ends of the enterprise technology stack. MLflow CVE-2026-64849 is a CVSS 9.3 server-side request forgery vulnerability in MLflow versions before 3.15.0. MLflow is the dominant open-source platform for AI and machine learning lifecycle management, used for experiment tracking, model registry, and deployment across both research and production AI environments. The flaw is in the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint. MLflow's webhook validation function checks only the original URL for safety, while the webhook delivery function follows HTTP redirects and re-resolves the hostname at the new destination without pinning the validated address. An attacker who can reach the MLflow Tracking Server, which is often exposed on port 5000 or 5001, can craft a webhook test request with a URL that redirects to an internal cloud metadata endpoint, such as http://169.254.169.254 on AWS, Azure, or GCP. MLflow follows the redirect and returns the response body to the attacker, including the instance identity document, IAM role credentials, and any secrets stored in the metadata service. WatchTowr confirmed active exploitation of CVE-2026-64849 as of August 18. The patch is MLflow 3.15.0. FUXA CVE-2026-25895 is a CVSS 9.5 vulnerability that combines missing authentication for a critical function with a path traversal component. FUXA is an open-source web-based SCADA/HMI platform for operational technology and industrial automation. The flaw allows an unauthenticated remote attacker to write arbitrary files to the server file system through path traversal. Writing to a location that the FUXA application loads or executes from converts the file write into remote code execution. VulnCheck observed a single source IP actively scanning for exposed FUXA instances beginning August 18, attempting to overwrite a core application file with empty data. VulnCheck estimates approximately 60 FUXA installations are publicly internet-accessible. No successful code execution has been confirmed in the wild for FUXA as of August 18, but the scanning pattern confirms attacker awareness of the flaw and active probing of exposed instances.
The two flaws represent different aspects of the same underlying dynamic: critical infrastructure platforms that were deployed without internet-exposure assumptions are now routinely internet-exposed, and attackers are targeting them accordingly. MLflow was designed for use within trusted data science environments where all users have legitimate access. Its exposure on accessible network ports gives attackers a path to the cloud credentials, AI provider API keys, and experiment secrets stored in or accessible through those environments. FUXA was designed for use within isolated OT network segments. The approximately 60 internet-accessible FUXA instances VulnCheck identified represent deployments where OT network segmentation was either not implemented or was implemented and then bypassed. A successful exploit against an internet-facing FUXA installation gives an attacker the ability to write arbitrary files to an industrial control system, which in the OT context can mean modifying configuration files that control physical processes.
Both CVEs were assigned and became targets within the same 24-hour window, consistent with the pattern this brief has documented since July: CVE assignment is the operational trigger for automated scanner deployment. WatchTowr's confirmation of MLflow exploitation within hours of CVE publication, alongside VulnCheck's FUXA scanning observation on August 18, reinforces that the gap between CVE assignment and first probing attempt is now reliably measured in hours rather than days. For MLflow specifically, the credential theft outcome is the concern that extends beyond the vulnerable MLflow instance itself. Cloud credentials obtained from the instance metadata service may be used to access production cloud infrastructure, S3 buckets, Azure Blob Storage, or Google Cloud Storage containing model artifacts, training data, and application secrets. Rotating those credentials after patching is the necessary second step.
  • Update MLflow to version 3.15.0 or later on all deployments. After patching, rotate any cloud credentials that were accessible to the MLflow instance through the instance metadata service or environment variables. If the MLflow Tracking Server was accessible on an external network, treat the cloud credentials available to that environment as potentially compromised and rotate before investigating whether exploitation occurred.
  • Restrict network access to the MLflow Tracking Server port to known trusted internal addresses. MLflow should not be accessible on external or untrusted network interfaces. If internet accessibility was unintentional, review the network configuration that allowed it, as the same misconfiguration may affect other components in the AI infrastructure stack.
  • For FUXA deployments, patch to the fixed version and then audit whether any FUXA instance is accessible from external networks. If internet accessibility is confirmed, review server filesystem contents for unexpected files and review application logs from August 18 onward for file write attempts against core FUXA application paths. The scanning behavior observed by VulnCheck targeted a specific core file; check whether that file's contents match the expected application state.
MLflow reaches the cloud metadata service and returns the credentials. FUXA writes arbitrary files to the OT server. Both became targets within hours of CVE assignment. Patch MLflow to 3.15.0 and rotate the cloud credentials. Patch FUXA and check whether any instance is internet-facing. In both cases the misconfiguration that allowed internet access is the structural problem to fix, not just the vulnerability.
03 HighOracleCritical Patch Update
Oracle's August CPU patches more than 1,000 vulnerabilities including a CVSS 9.9 WebLogic Server takeover flaw across two dozen products
Oracle's quarterly Critical Patch Update is one of the largest single patch events in enterprise IT. This release addresses more than 460 remotely exploitable bugs across Oracle Database, WebLogic Server, MySQL, E-Business Suite, Fusion Middleware, and others. CVE-2026-60702 in WebLogic is rated CVSS 9.9 and allows complete server takeover without authentication. Oracle CPUs have a documented history of rapid weaponization.
Total patches1,000+ CVEs
24+ products
Remote exploitable460+ bugs
no auth required
Lead CVECVE-2026-60702
CVSS 9.9
WebLogic takeover
Release dateAugust 19, 2026
ExploitationNot confirmed yet
Prior CPUs exploited
within weeks
Oracle released its August 2026 Critical Patch Update on August 19, 2026. The CPU is Oracle's quarterly security release, addressing vulnerabilities across its full product portfolio. This release covers more than 1,000 CVEs across more than two dozen product families. More than 460 of the patched vulnerabilities are remotely exploitable without requiring authentication, the highest-severity category in terms of attack accessibility. Affected product families include Oracle Database Server, Oracle WebLogic Server, Oracle MySQL, Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Java SE, Oracle Communications applications, Oracle Retail applications, and Oracle Financial Services applications. CVE-2026-60702, rated CVSS 9.9, is a critical flaw in Oracle WebLogic Server. WebLogic is an application server widely deployed for Java EE applications in enterprise environments, including financial services, insurance, and government systems. The CVSS 9.9 score indicates an unauthenticated, remotely exploitable flaw with near-maximum impact on confidentiality, integrity, and availability. SecurityWeek described the flaw as allowing complete server takeover. Oracle published nine specific WebLogic fixes in the August CPU. Exploitation has not been confirmed in the wild as of August 19. Oracle's security advisory recommends applying the CPU patches to all affected product versions without delay and notes that customers who delay applying patches expose themselves to risk from exploits that specifically target the vulnerabilities addressed in the current CPU.
Oracle WebLogic Server carries a sustained exploitation history. CVE-2023-21839, CVE-2020-14882, and CVE-2020-14750 were all critical WebLogic vulnerabilities exploited to deploy cryptocurrency miners and ransomware within days to weeks of disclosure. The CVSS 9.9 score on CVE-2026-60702 places it in the category of prior WebLogic flaws that attracted rapid weaponization. Oracle E-Business Suite and Fusion Middleware vulnerabilities in prior CPUs were similarly exploited in narrow windows after publication. The operational challenge with Oracle CPUs is that the products involved, WebLogic application servers, Oracle Databases, and EBS installations, are typically production systems with complex change management requirements and long patch testing cycles. That friction is precisely why Oracle CPUs are a documented attacker target: the gap between patch availability and enterprise deployment is reliably longer for Oracle products than for operating system patches.
Oracle's CPU release coincides with an unusually heavy patching week: the August Patch Tuesday batch with two newly confirmed exploited CVEs, the SAP Commerce Cloud CVSS 10.0 emergency note that reached active exploitation within 24 hours, the Cisco ASA deadline that passed August 14, and the MLflow and FUXA exploitation documented today. Enterprise security teams processing this week's vulnerabilities are managing the highest volume of concurrent urgent items in any single week this brief has covered. The Oracle CPU is the largest single release and the one that organizations with Oracle infrastructure are most likely to defer into next quarter's patching cycle. CVE-2026-60702's CVSS 9.9 rating argues against that deferral. If full CPU application is not feasible this week, applying the WebLogic patches specifically, and any patches for internet-facing Oracle components, reduces the most accessible attack surface while the broader CPU roll-out proceeds.
  • Apply the August 2026 Oracle Critical Patch Update to all Oracle product installations. If full CPU application cannot be completed this week, prioritize patches for internet-accessible components first: Oracle WebLogic Server deployments reachable from external networks, Oracle E-Business Suite web-facing components, and Oracle Fusion Middleware services exposed beyond internal networks.
  • Apply the WebLogic patches addressing CVE-2026-60702 on an expedited basis given the CVSS 9.9 rating and WebLogic's documented exploitation history. WebLogic patches within the Oracle CPU are available as separate patch sets for specific WebLogic versions and can be applied independently of the broader CPU to address the highest-severity items first.
1,000 vulnerabilities. 460 remotely exploitable without credentials. CVSS 9.9 WebLogic takeover. Prior WebLogic flaws were exploited within weeks. If the full CPU cannot apply this week, the WebLogic patches and anything internet-facing go first. The rest follows in sequence.
Cross-source standouts
01
The week of August 12 to 19: the highest concurrent patch urgency this brief has documented in a single calendar week
Counting the items that required immediate action between August 12 and August 19: Microsoft Patch Tuesday with one confirmed exploited zero-day and a wormable unauthenticated RCE (Issue 106). SAP August Patch Day with four critical notes (Issue 106), followed by an emergency note for a CVSS 10.0 Commerce Cloud flaw that reached active exploitation at scale within 24 hours (Issue 107, Issue 110). Adobe ColdFusion CVSS 10.0 Priority 1 emergency (Issue 108). Cisco ASA with a federal deadline of August 14 (Issue 108). GeoServer zero-day with no patch (Issue 108). LiteLLM 153GB credential archive (Issue 107). vCenter and Apple macOS confirmed exploited and added to KEV (Issue 109, this issue). Zoom Zoomsday zero-click patched August 11 (Issue 110). SAP CVE-2026-58231 confirmed exploited at scale (Issue 110). Ray AI framework on KEV with a deadline of August 20 (Issue 111). GitLab emergency patch (Issue 111). Windows IKE and SharePoint confirmed exploited and added to KEV (this issue). Oracle CPU with 1,000 vulnerabilities (this issue). MLflow and FUXA exploitation begins (this issue). No previous week in this brief's coverage approached this volume of concurrent items each warranting immediate or same-day attention. The structural observation is that this is not a spike. August 2026 represents the sustained new baseline. The operational response is not to work faster on the same workflow. It is to have a clear triage framework that can reliably identify the two or three items in any given day that require immediate action, and to stop spending equivalent time on the items that can wait.
02
MLflow, FUXA, Ray: the common thread across three AI and OT exploitation events this week
Three platforms appeared in this week's CyberSip issues as active exploitation or scanning targets: Ray (Issue 111), MLflow (this issue), and FUXA (this issue). All three share a structural characteristic: they were designed for use in trusted environments and have been deployed with the assumption that network access controls would restrict who could reach them. Ray was designed for trusted compute clusters. MLflow was designed for internal data science environments. FUXA was designed for isolated OT network segments. All three are now discoverable via Shodan or similar tools in internet-accessible configurations. All three have critical vulnerabilities that are being actively targeted. The connecting principle is not that these platforms are poorly written. It is that the gap between the network environment they were designed for and the network environment they are actually deployed in creates an attack surface that the software itself was never designed to defend against. Unauthenticated access to Ray's job API, MLflow's webhook endpoint, and FUXA's file management function is expected and by design in a trusted network. It becomes a critical vulnerability the moment that trusted network boundary is crossed by an internet-facing deployment. The remediation in all three cases is not only patching the specific CVE. It is restoring the network boundary that the software assumed would be present when it was designed.
Still watching
Days 2–5
Ray CVE-2025-62593 (Issue 111 · CISA KEV August 17, deadline August 20 — tomorrow) — upgrade to Ray 2.52.0. Restrict ports 8265 and 8000 to trusted networks. For clusters that were network-accessible before today, audit job history and rotate AI provider keys, cloud credentials, and any tokens accessible to the cluster environment.
Day 2
Zoom CVE-2026-53413 Zoomsday (Issue 110 · zero-click RCE, patched August 11) — update to Workplace 7.1.5 or 7.0.6. Confirm client version in Help, About Zoom. E2EE meetings are not covered by server-side filtering; client patch is the only protection.
Day 5
GeoServer zero-day (no CVE, no patch) (Issue 108 · active probing, jsonArrayContains) — no patch available as of August 19. Restrict public access to WFS endpoints. Limit SQL Server database account permissions to block xp_cmdshell. Monitor jsonArrayContains filter logs since August 12.
Day 7+
Atlassian Rovo content-borne prompt injection (Issue 104 · PromptArmor, reported May 2026) — URL parameter path patched July 8. Content-borne path status unconfirmed as of August 19. Scope Rovo access tightly and audit Rovo Connector connections to external platforms until Atlassian confirms both injection paths are closed.
Day 7+