TODAY
Nine CVEs newly exploited; patch Microsoft, Ivanti, and Progress now.
THE THREE
- KEV#1 · CVE-2026-33824
Microsoft
What: This flaw in Microsoft's IKE Service — used in Windows VPN and secure networking — lets attackers remotely take over systems with no user interaction required. With a 73% exploit probability and confirmed active exploitation, any Windows system with IKE exposed is a target.
Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Microsoft's patch for CVE-2026-33824 immediately across all Windows systems.
- KEV#2 · CVE-2026-8037
Progress
What: Progress LoadMaster load balancers have a command injection flaw that unauthenticated attackers are already exploiting in the wild — essentially a front door anyone on the internet can walk through to run their own commands on your appliance. Exploit probability is effectively 100%.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Progress LoadMaster firmware now and restrict management interfaces to trusted IPs.
- KEV#3 · CVE-2026-10520
Ivanti
What: Ivanti Sentry, which sits at the edge managing mobile device traffic, has a maximum-severity flaw (CVSS 10.0) allowing unauthenticated remote attackers to gain full root control — this is as bad as it gets, and it's being actively exploited. Any exposed Sentry appliance should be treated as potentially compromised.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Ivanti Sentry immediately and audit logs for signs of unauthorized access.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 291
- Indicators
- 593k
- Feeds live
- 18
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.