Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Hype scores and KEV entries in August 2026: what changed?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: August’s vulnerability landscape showed a widening gap between online attention and operational risk, with JFrog Artifactory’s CVE-2026-82329 peaking at a hype score of 62 while CISA later added it to KEV, according to Intruder’s cvemon analysis. Intruder’s view is that exploitability, privilege impact, and placement in build pipelines matter more than social attention when prioritising remediation.

NHIMG editorial — based on content published by Intruder: August cvemon coverage of trending vulnerabilities and KEV additions

By the numbers:

  • Intruder said xss2shell, CVE-2026-64638, was disclosed on 7 August and rated CVSS 8.9.
  • Intruder noted that another 31 CVEs picked up a KEV entry in August without trending on social media.
  • Microsoft’s Entra ID bug, CVE-2026-69836, was published as a CVSS 10.0 issue before being corrected as not exploited in the wild.

Questions worth separating out

Q: How should security teams prioritise vulnerabilities when exploit timelines are shrinking?

A: Prioritisation should combine exploitability, reachability, internet exposure, identity proximity, and business criticality.

Q: Why do pre-auth bugs in login or admin paths create such high risk?

A: They remove the need for valid credentials before the attacker crosses the first trust boundary.

Q: What breaks when a vulnerable platform also holds secrets or release rights?

A: The vulnerability stops being local to one application and becomes a path into credentials, signing material, or deployment authority.

Practitioner guidance

  • Re-rank vulnerabilities by privilege reach Score externally reachable issues higher when they sit in admin consoles, authentication layers, artifact stores, or other trust brokers that can expose credentials or alter access paths.
  • Add identity impact checks to KEV triage When a KEV-listed flaw touches a login flow, token service, CI/CD tool, or repository, require an access-path review before assigning remediation priority.
  • Inventory secrets in high-trust platforms Map where build systems, repositories, and control planes store API keys, tokens, certificates, or signing material so compromise severity reflects actual identity reach.

What's in the full report

Intruder's full analysis covers the operational detail this post intentionally leaves for the source:

  • Monthly CVE-by-CVE activity history for the vulnerabilities that trended or entered KEV
  • Intruder's specific reasoning for why xss2shell was underhyped despite a working proof of concept
  • The live cvemon status view for each vulnerability and its current hype score
  • The broader August list of KEV additions, including backfilled entries from earlier years

👉 Read Intruder's August cvemon analysis of exploited CVEs and hype scores →

Hype scores and KEV entries in August 2026: what changed?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Attention-driven triage is structurally weak for vulnerability management: hype scores track discussion, not attacker value. August’s pattern shows why teams need exploitability, trust placement, and privilege reach as the primary sorting inputs. A vulnerability inside a build or identity control plane can matter more than a louder issue elsewhere. Practitioners should re-rank remediation using operational blast radius, not social momentum.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how limited identity oversight still is in many environments.

A question worth separating out:

Q: How do teams tell whether a CVE is a real operational threat?

A: Look for three signals: active exploitation or KEV entry, a working proof of concept, and a path to privileged or high-trust assets. If those line up, treat the issue as an urgent exposure event even when it is not generating much discussion. The key test is whether the flaw can reach identities, secrets, or control functions.

👉 Read our full editorial: August's exploited CVEs show hype rarely matches real risk



   
ReplyQuote
Share: