Five CVEs this week where the exploitation flag came apart — four where two authorities disagree outright, in both directions and once in this constituency's own national feed, and one where no feed had a flag to disagree about
Most vulnerability-management processes in this constituency now rank on an exploitation flag. It is the right instinct — exploitation status separates the flaws that need an out-of-band response from the ones the patch cycle already handles — and it is the reason CISA's Known Exploited Vulnerabilities catalogue and ENISA's EU Vulnerability Database exploited feed have become load-bearing inputs rather than reference material. Five records this week show what happens when that flag is treated as a property of the vulnerability rather than as an opinion held by a particular authority on a particular date. Four of the five are outright disagreements, one of them in the feed a Swiss defender has the best reason to trust; the fifth is the case where no feed had a flag to disagree about at all.
Two where the catalogue says yes and the vendor still says no. CISA added CVE-2026-33824 to its catalogue on 2026-08-18, recording it as a double free in the Microsoft Internet Key Exchange service extensions that could enable remote code execution (CISA KEV catalog v2026.08.21, 2026-08-21); the flaw is pre-authentication and reachable on UDP 500 and 4500, per this pipeline's coverage of 10 and 19 August. Microsoft's record for the same CVE has not been revised since it was published on 14 April 2026, and still records exploitation as no with an exploitability assessment of "Exploitation Less Likely" (Microsoft Security Response Center, 2026-04-14). The same update added CVE-2026-55040, which the catalogue records as a weak-authentication flaw in SharePoint allowing an unauthorized attacker to bypass a security feature over a network (CISA KEV catalog v2026.08.21, 2026-08-21); Microsoft's record for that one, unrevised since 14 July 2026, likewise still records exploitation as no (Microsoft Security Response Center, 2026-07-14). An estate that ranks Windows CVEs on the vendor's own exploited field — a common and otherwise entirely reasonable design, since the vendor is the authority on its own product — had the IKE flaw sitting four months deep in a backlog on the week a federal catalogue classed it as under attack.
One where the vendor says no and the European feed still says yes. Microsoft published CVE-2026-69836 on 2026-08-20, a deserialization flaw in Entra ID rated CVSS 10.0, and revised the record the following day with a note stating the vulnerability was not exploited in the wild and that the change was informational only (Microsoft Security Response Center, 2026-08-21). The revision wording only makes sense if the field briefly held a different value while the record was live. ENISA's EU Vulnerability Database record for the same CVE was last updated on 2026-08-22 — a day after the correction — and still carries it on the exploited feed with an exploited-since date of 2026-08-21, citing as its only reference the Microsoft page that now says the opposite (ENISA EU Vulnerability Database, 2026-08-22). This is a cloud-service CVE with nothing for any tenant to install, so the cost is not exposure: it is an out-of-band escalation on a maximum-severity identity-plane record that nobody can act on.
One in the constituency's own national feed, and on the thinnest basis of the five. On 2026-08-21 Switzerland's NCSC amended its advisory for CVE-2026-19490, the CVSS 9.3 authentication bypass on Citrix NetScaler Gateway and AAA virtual servers, changing the recorded exploitation status from unknown to actively exploited; the only supporting reference the amendment cites is a single post on a social-media platform (NCSC-CH, 2026-08-21). CERT-EU's advisory of two days earlier records no exploitation, and neither does the research firm whose analysis both authorities relay (CERT-EU, 2026-08-19). This pipeline does not treat social-media-only sourcing as establishing exploitation and has not adopted the flag — but that is precisely the point: a Swiss reader whose vulnerability process ingests its own national CERT's feed, which is the most defensible feed choice available to this constituency, now has an actively-exploited flag on an internet-facing appliance that no other authority carries.
And one where there was no flag to disagree about. Zimbra shipped ZCS 10.1.20 on 2026-07-21 fixing a pre-authentication command injection in its SNMP monitoring component, described at the time only in general terms; the identifier CVE-2026-73570 was not published until 2026-08-13, and ENISA's database now records the flaw as exploited since 2026-08-18 (ENISA EU Vulnerability Database, 2026-08-13). For four weeks between the patch and the identifier, there was no record for any exploitation feed to attach a flag to — a CVE-driven patch process could not see the flaw at all, let alone rank it.
A prior weekly recorded six disclosures in which the CVE identifier itself failed as the pivot a vulnerability process turns on: advisories built on CVEs that an LLM had invented, exploited and CVSS 10.0 flaws shipping with no CVE assigned at all, one vendor issuing one CVE per bug class rather than per bug. This week's four are the same failure moved one field to the right. The identifiers here exist, resolve correctly, and describe real flaws accurately; what disagrees is the single boolean that most estates now use to decide whether to work the weekend.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.