cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Gitea's RCE Through Git Hook Installation Was Confirmed Exploited in a Day
CVE-2026-60004, remote code execution in Gitea via the diffpatch API and Git hook installation, went from disclosure to confirmed exploitation in roughly 24 hours.
VMware vCenter's Syslog Server Had a Path Traversal Bug CISA Ties to Ransomware
CVE-2026-59310, a directory traversal vulnerability in vCenter's Syslog server leading to code execution, carries CISA's confirmed ransomware campaign flag.
One CVE From 2019, One From 2023: Both Just Confirmed Exploited in 2026
A Microsoft SQL Server RCE from 2019 and an ownCloud authentication bypass from 2023 both entered CISA's KEV catalogue in the same week of August 2026 — years after their original disclosure.
Oracle's WebLogic Proxy Plug-in Bug Sat at CVSS 10.0 for Seven Months Before Confirmed Exploitation
CVE-2026-21962, an access control failure in the Oracle HTTP Server / WebLogic Server Proxy Plug-in, went from January disclosure to August KEV confirmation — seven months later.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.