cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
29 articles
CVE-2026-8037: When the Function That Escapes Your Input Is the Bug
Progress Kemp LoadMaster's flaw lives inside escape_quotes(), the routine meant to neutralise dangerous input. It fails to null-terminate, turning a sanitiser into unauthenticated command injection.
CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port
An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.
The Patch That Wasn't: CVE-2026-18577 and the Incomplete-Fix Problem
N-able patched an authentication bypass in N-central. Attackers found what the patch missed and used it as a zero-day, pivoting into Microsoft 365 and Okta. Incomplete fixes are their own bug class.
CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution
Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.
Your 30-Day Patch SLA Meets a 48-Hour Exploitation Window
88% of exploitation against vulnerabilities with a public PoC now happens within 48 hours. No organisation patches everything that fast. The fix is a smaller fast lane, selected automatically.
CVE-2026-34486: When the Encryption You Configured Doesn't Apply
Apache Tomcat's EncryptInterceptor exists to encrypt cluster replication traffic. CVE-2026-34486 lets that protection be bypassed — the config says encrypted, the wire says otherwise.
A CVSS 5.3 That Cisco Rated High: Static Credentials in Firewall Management Center
CVE-2026-20316 scores 5.3. Cisco rated its security impact High anyway, and CISA added it to the KEV catalogue. On a firewall management appliance, the base score measures the wrong thing.
CVE-2025-64446 in Fortinet FortiWeb: Patch Posture & SBOM Response
FortiWeb path traversal + RCE scored CVSS 9.1 and entered CISA KEV after months of targeted exploitation. Defender playbook for the WAF emergency.
Vulnerability fatigue and the case for risk-based prioritization
48,185 CVEs were published in 2025 alone. Most teams can't triage that volume — reachability and exploit maturity data show which ones actually matter.
A prioritization framework for triaging security alerts at scale
Only 2.6% of CVEs tracked in 2019 saw real-world exploitation, per Kenna Security/Cyentia — yet most teams still triage by CVSS alone. Here's a better framework.
A Step-by-Step Methodology for Mapping and Prioritizing Attack Surface
CVE-2023-34362 sat in one internet-facing file-transfer server and still produced thousands of downstream breaches — attack surface mapping is what catches that server before Cl0p does.
Beyond vulnerability management: a risk-based approach to AppSec
Fewer than 5% of published CVEs are ever exploited in the wild, yet most teams still triage by raw count — here's the exploitability-first alternative.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.