TODAY
Windows, macOS, and SharePoint all hit with active exploits this week.
THE THREE
- KEV#1 · CVE-2026-33824
Windows
What: This flaw in Windows IKE Extension (the component that handles VPN-style encrypted connections) lets an attacker run their own code on your Windows machines over the network — no login required. It was added to CISA's exploited list two days ago with a 78% probability of exploitation, meaning real attacks are happening now.
Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · 78% exploit odds · New this week
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Microsoft's patch for CVE-2026-33824 on all Windows systems immediately.
- KEV#2 · CVE-2026-8037
Progress
What: Progress LoadMaster is a load balancer used to route web and app traffic; this command injection flaw lets anyone on the internet run arbitrary commands on the appliance with no credentials at all. With a 99% exploit probability and active exploitation confirmed, any exposed LoadMaster is effectively owned.
Why it moved: Actively exploited · Widely deployed · Critical severity · 99% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch or isolate all Progress LoadMaster appliances from public internet access now.
- KEV#3 · CVE-2026-34486
Apache
What: Apache Tomcat powers countless internal and public-facing web applications; this flaw strips away encryption protections and can be chained with a previously known vulnerability (CVE-2025-24813) to escalate impact, potentially leading to data theft or server takeover. With an 83% exploit probability and active exploitation, any unpatched Tomcat instance is a target.
Why it moved: Actively exploited · Everyone runs this · 83% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Apache Tomcat to a patched version and verify EncryptInterceptor is functioning.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 66M
- Threat actors
- 356
- Indicators
- 566k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.