TODAY
Windows, macOS, and SharePoint all hit with active exploits this week.
THE THREE
- KEV#1 · CVE-2026-33824
Windows
What: This Windows flaw lets an attacker run their own code on your machine over the network with no login required — KEV-listed just 4 days ago with a 78% exploit probability, meaning active attacks are already happening. Any unpatched Windows system reachable on the network is at immediate risk of full compromise.
Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · 78% exploit odds · New this week
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the Microsoft patch for CVE-2026-33824 to all Windows systems now.
- KEV#2 · CVE-2026-8037
Progress
What: Progress LoadMaster load balancers have a command injection flaw that unauthenticated attackers are exploiting at near-certainty (99% exploit odds) — a compromised load balancer means attackers sit in front of all your internal traffic. If you run LoadMaster, assume it is a target right now.
Why it moved: Actively exploited · Widely deployed · Critical severity · 99% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Progress LoadMaster to the patched version immediately.
- KEV#3 · CVE-2026-34486
Apache
What: Apache Tomcat is stripping encryption from sensitive data in transit, and this flaw chains with a previously known vulnerability (CVE-2025-24813) to amplify the damage — attackers can exploit both together for a more powerful attack. Any org running Tomcat-based web apps is exposed to data theft or server takeover.
Why it moved: Actively exploited · Everyone runs this · 83% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Apache Tomcat and verify EncryptInterceptor is functioning correctly.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 359
- Indicators
- 570k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.