cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Eleven Microsoft CVEs From 2008 to 2013, All Confirmed Exploited This Past Year
A Windows buffer overflow from 2008, IE bugs from 2010, an Office flaw from 2009 — eleven old Microsoft vulnerabilities entered CISA's KEV catalogue, several on the exact same day.
CISA Gave You Three Days: What the KEV Deadlines Say About Your Patch Process
Of the 103 vulnerabilities CISA added to the exploited catalogue since June, 75 carry a three-day remediation deadline. That is shorter than most release cycles, and it is an architecture requirement rather than a scheduling problem.
A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706
An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.
Four Artifactory CVEs in Sixteen Days: The Registry Is the Supply Chain
JFrog Artifactory had never appeared in CISA’s exploited-vulnerabilities catalogue. Between 27 August and 11 September 2026 it gained four entries, including unauthenticated administrative access under default configuration.
Apple Patched a Network-Exploitable Auth Bug Across Five Concurrent macOS Releases
CVE-2026-65400, an authentication issue Apple fixed with 'improved state management,' was backported across Golden Gate, Sequoia, Sonoma and two Tahoe releases at once.
Arista's SD-WAN Orchestrator Had a Perfect-10 Privileged-Access Bug
CVE-2026-16812 gives a remote attacker access to privileged internal functionality on Arista's on-premises VeloCloud Orchestrator — the single console managing an entire SD-WAN fleet.
Zimbra's Optional SNMP Monitoring Feature Became a Remote Code Execution Path
CVE-2026-73570 requires the optional zimbra-snmp package and SNMP notifications enabled — exactly the configuration a more security-conscious mail admin was likely to have set up.
A Host-Header Bug in Starlette Affects Every FastAPI App Built On It
CVE-2026-48710, a moderate-severity Host-header validation gap in the Starlette framework underlying FastAPI, was still confirmed exploited — CVSS is not the only signal that matters.
Sangoma Switchvox's Phone-Provisioning Feature Was an Unauthenticated SQL Injection
CVE-2026-9586 abuses Switchvox's Polycom phone-provisioning endpoint, concatenating device-submitted XML directly into a SQL query with no authentication required.
Lantronix EDS5000's Failed-Login Logging Was Itself the Vulnerability
CVE-2025-67038 triggers on a failed login attempt alone: the device server shells out to write a log entry, concatenating the attacker-supplied username unsanitised into the command.
PTC Windchill and FlexPLM's Deserialization RCE Is Confirmed Tied to Ransomware
CVE-2026-12569, a deserialization RCE in PTC's product lifecycle management platforms, carries CISA's confirmed ransomware campaign flag — a notable finding in specialised industrial software.
Adobe ColdFusion's Path Traversal Bug Reached Full Code Execution
CVE-2026-48282, CVSS 10.0, is a path traversal vulnerability in Adobe ColdFusion that leads directly to arbitrary code execution — the platform's latest entry in a long history of critical CVEs.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.