Executive Summary
August 2026 proved arelentless month for defenders, as CISA added 32 vulnerabilities to its KnownExploited Vulnerabilities catalog, confirming that attackers were activelybreaking into real systems across a wide sweep of enterprise technology.Microsoft led the additions with five flaws, followed by two apiece fromPaperCut NG/MF, N-able N-central, TrueConf, and Red Hat, with single entriesspanning IBM, Apache, N-able, JetBrains, Progress, Metabase, Cisco, RayProject, Apple, Broadcom, MLflow, Synacor, Oracle, Gitea, Citrix, Ajax.NETProfessional, ownCloud, and JFrog. The catalog additions reached from operatingsystems and virtualization platforms to print management, artifactrepositories, AI tooling, and decade-old open-source components, underscoringhow attackers weaponized both freshly disclosed flaws and long-forgotten oneswith equal ease.
Beyond the catalog, activeexploitation struck platforms including Palo Alto Networks, BeyondTrust, andCitrix, several within days of disclosure. The month also spotlighteddetermined state-aligned and financially motivated actors: the China-linkedQTFY group breached US critical infrastructure using its custom scanning andbotnet platforms, the Chinese-speaking UAT-10147 group deployed thecross-platform SPECTRE backdoor while folding AI into its operations, and theMirai-derived Evooo1Bot botnet turned internet-facing edge devices intostealthy proxy relays and attack nodes.
Ransomware pressureintensified in parallel, with Qilin topping the month at 162 affectedorganizations, followed by TheGentlemen with 111 and Cl0p with 85.

