Windows IKE RCE: Patched in April, Exploited Now

CVE-2026-33824 Windows IKE RCE is now actively exploited despite an April patch. CVSS 9.8, no auth needed. See who's affected and what to check today.

CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…

Read More

Progress LoadMaster CVE-2026-8037: 792 Attacks Logged

Progress LoadMaster CVE-2026-8037 (CVSS 9.6) is on CISA's KEV list after 792 exploit attempts. Unauthenticated root RCE — patch now.

Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…

Read More

VMware vCenter CVE-2026-59310: Germany Hit Hardest

VMware vCenter CVE-2026-59310, a CVSS 9.8 flaw, is under active exploitation in 47 countries — Germany is hit hardest. What to do now.

VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…

Read More

Top 5 Cybersecurity News Stories August 14, 2026

Cybersecurity News Stories August 14, 2026 featured image showing five connected attack vectors — Windows kernel rootkit, OT network lateral movement, ERP platform RCE, analytics credential exposure, and MSP management plane bypass — unified by an amber threat thread in a dark enterprise security environment`

This week’s Cybersecurity News Stories August 14, 2026 arrives during a week when defenders discovered something uncomfortable: the tools and infrastructure they depend on to manage, monitor, and protect their environments were themselves the target. A nation-state rootkit disabled Windows security callbacks at the kernel level. A heating plant lost control of its steam turbine…

Read More

TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover

TeamCity CVE-2026-63077 RCE

TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…

Read More