cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Oracle E-Business Suite's Payments Module Had an 'Easily Exploitable' Unauthenticated Bug
CVE-2026-46817, which Oracle itself describes as easily exploitable, sits in the Payments component of Oracle E-Business Suite versions 12.2.3 through 12.2.15.
Check Point SmartConsole's Login Bypass Handed Out Real Administrator Tokens
CVE-2026-16232 let an unauthenticated attacker obtain a genuine SmartConsole login token with full administrative privileges — confirmed exploited the same day it was disclosed.
Splunk's Bundled PostgreSQL Sidecar Was the Vulnerable Component, Not Splunk Itself
CVE-2026-20253 lets an unauthenticated user create or truncate arbitrary files on Splunk Enterprise through a bundled PostgreSQL sidecar service, not the core application.
Metabase's Password Reset Endpoint Was a CVSS 10.0 SQL Injection
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's own password-reset flow and gain full administrator access to the connected BI instance.
Six More Old CVEs Just Got Confirmed Exploited, One From 2008
An eighteen-year-old Cisco IOS CSRF bug, two 2015 Red Hat findings, a 2021 deserialization flaw, and more — six vulnerabilities spanning nearly two decades, all confirmed exploited in 2026.
One Linux Kernel Bug From This Year, One From 2022 — Confirmed Exploited the Same Day
An IPv6 fragmentation bug disclosed weeks earlier and a 2022 watch_queue vulnerability both entered CISA's KEV catalogue on the same day in August 2026.
Two WordPress CVEs, and NVD Says They're the Same Attack Chain
WordPress core's CVE-2026-63030 explicitly references CVE-2026-60137 in its own NVD description — a documented exploitation chain, not two coincidentally similar bugs.
Four Microsoft CVEs Describe a Complete Access-to-Domain-Control Chain
One unauthenticated RCE and three local privilege-escalation bugs across Windows and Active Directory Federation Services, confirmed exploited between July and September 2026.
Two FortiOS CVEs Span Six Release Lines Going Back Years
A heap-based buffer overflow and an information-exposure bug in FortiOS, both confirmed exploited in 2026, span version ranges reaching back through years of release history.
Cisco's Email Gateway, ASA and Unified Communications Manager All Confirmed Exploited
Three different Cisco product lines — Secure Email Gateway, Firewall ASA/FTD, and Unified Communications Manager — each had a vulnerability confirmed exploited between June and September 2026.
Three Maximum-Severity UniFi OS CVEs, Same Day, Same Product
Ubiquiti UniFi OS had three CVSS 10.0 vulnerabilities — command injection, path traversal, and access control failure — all confirmed exploited on the same day in June 2026.
Two Chrome V8 Vulnerabilities Confirmed Exploited Within Five Days
Two memory-safety bugs in Chrome's V8 engine — out-of-bounds write and type confusion — both confirmed exploited within V8's sandbox in early September 2026.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.