VYPR
AI Brief2026-08-11· generated Aug 11, 2026

Microsoft Leads KEV Additions Amidst Critical Flaw Surge

Microsoft leads with five critical vulnerabilities added to KEV, including Outlook RCE, alongside critical flaws in Joomla, ProxySQL, and web apps.

Microsoft has seen a surge of activity around several critical vulnerabilities, with five added to the CISA Known Exploited Vulnerabilities (KEV) catalog. CVE-2024-21413, a critical remote code execution flaw in Microsoft Outlook, is particularly concerning due to its high exploitability. Also added are CVE-2022-41080 (Exchange Server privilege escalation), CVE-2024-21412 (Internet Shortcut spoofing), CVE-2024-21338 (Windows Kernel privilege escalation), and CVE-2023-36884 (Windows Search RCE), the latter of which was highlighted in a Q1 2026 threat report by Securelist. Organizations must prioritize patching these vulnerabilities to mitigate the risk of compromise.

Several other critical vulnerabilities warrant attention, including CVE-2021-26424 and CVE-2021-34458, both critical RCEs in the Windows TCP/IP stack and Windows Kernel respectively. Microsoft also disclosed CVE-2021-26432, a critical RCE in the Windows Services for NFS ONCRPC XDR driver.

Beyond Microsoft, a critical RCE in Joomla's Fabrik extension (CVE-2026-66915) allows unauthenticated attackers to exploit the ajax_cal feature. In database infrastructure, ProxySQL (versions 2.0.0-3.0.8) has a critical flaw (CVE-2026-48772) where it incorrectly accepts JWTs signed with unsupported algorithms, enabling authentication bypass.

Security teams should also be aware of critical vulnerabilities in web applications and development tools. CVE-2026-72593 and CVE-2026-72592 describe critical RCE and file manager access flaws in dulldusk/phpfm through v1.8.0, exploitable by unauthenticated attackers. Similarly, alseambusher/crontab-ui through v0.4.2 contains critical OS command injection vulnerabilities (CVE-2026-72590, CVE-2026-72589) allowing unauthenticated remote attackers to manipulate cron jobs or execute arbitrary commands via crafted requests or imported files. Finally, duhow/xiaoai-patch has a critical OS command injection flaw (CVE-2026-72580) affecting Xiaomi smart speakers.

Synthesized by Vypr AI