CISA
5 published articles
Known Exploited Vulnerabilities
Active exploits push Progress LoadMaster flaw onto CISA's must-patch list
CISA's KEV catalog now includes CVE-2026-8037, an actively exploited command injection flaw in Progress LoadMaster. Under BOD 26-04, the entry turns a one-line advisory into a federal patch priority, and CISA urges every organization to treat the list the same way.
2026-08-10
CISA
CISA adds two actively exploited flaws to its must-patch catalog
CISA added CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog, requiring rapid remediation for federal agencies. The advisory definitions behind these listings clarify how industrial control and medical device vulnerabilities are disclosed and mitigated.
2026-08-02
CISA KEV
Cisco flaw on CISA's KEV list: patching is not enough anymore
CISA adds a Cisco firewall password flaw to its KEV catalog. Under BOD 26-04, federal agencies must now investigate for pre-patch exploitation, not just apply the patch. The same expectation applies to recent Check Point and Microsoft SharePoint vulnerabilities.
2026-08-02
Cybersecurity
Two new CISA alerts, one hard question: did they get in before you patched?
CISA adds CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog. Under BOD 26-04, agencies must now check for pre-patch compromises and prioritize by risk, making breach detection just as critical as patching speed.
2026-07-25
Cybersecurity
CISA adds microsoft sharepoint server vulnerability to exploited list as parallel ransomware attacks emerge
CISA flags CVE-2026-45659 under active exploitation, urging federal agencies to patch by July 4, 2026. Microsoft details parallel Storm-2603 and unknown actor activity using sharepoint vulnerabilities and tunneling tools.
2026-07-02