U.S. Cybersecurity and Infrastructure Security Agency

Entity category: organization

AI & Tech

CISA Orders Federal Agencies to Patch Zyxel Data Theft Flaw

CISA has issued an urgent mandate requiring federal agencies to patch CVE-2026-7273, a critical vulnerability in Zyxel GS1900 switches that…

Read More »
AI & Tech

CISA Automates Vulnerability Reporting Platform

As of September 17, 2026, CISA officially transitioned from the legacy VINCE system to VINCE-NT, a modernized platform managed directly…

Read More »
AI & Tech

ScreenConnect Zero-Day Now Under Active Attack

CISA confirmed that threat actors are actively exploiting CVE-2026-84869, a critical zero-day vulnerability in ConnectWise’s ScreenConnect software that allows unauthorized…

Read More »
AI & Tech

Zimbra Servers Compromised; Patched Citrix NetScaler Flaw Exploited

Security researchers report a surge in attacks on unpatched enterprise infrastructure, with active exploitation of critical vulnerabilities in Zimbra, Citrix…

Read More »
BigTech Companies

CISA orders federal patch for exploited TrueConf Server bugs

CISA has added two actively exploited TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) to its KEV catalog, mandating that U.S. federal…

Read More »
BigTech Companies

Windows IKE Extension RCE Flaw Actively Exploited

CISA warns that threat actors are actively exploiting CVE-2024-38063, a critical 9.8-severity remote code execution vulnerability in Windows IKE Service…

Read More »
Business

SAP Commerce Cloud max-severity bug now exploited in attacks

CVE-2026-58231, a critical (CVSS 10.0) unauthenticated remote code execution vulnerability in SAP Commerce Cloud, is now being actively exploited just…

Read More »
AI & Tech

Cisco flags high-severity ClamAV bugs with public exploits

Cisco disclosed two high-severity DoS vulnerabilities (CVE-2026-20337, CVE-2026-20338) in ClamAV's ZIP parser within Secure Endpoint Connector, triggered by malicious ZIP…

Read More »
Artificial Intelligence

CISA: Hackers Exploiting Langflow, N-central, Tomcat Flaws

CISA has mandated that federal agencies patch three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within 72…

Read More »
AI & Tech

CISA issues new open-source software guidance

CISA released a new guide outlining how federal agencies should manage open source software (OSS) risks, including evaluating projects before…

Read More »
Business

CISA warns of cyberattacks on U.S. water utilities

CISA issued an urgent warning about a sharp rise in attacks on internet-exposed programmable logic controllers (PLCs) in the water…

Read More »
AI & Tech

CISA unveils updated SBOM baseline standard

CISA's 2026 Minimum Elements for SBOM supersedes the 2021 NTIA framework, expanding on core data fields (supplier, component names, versions)…

Read More »
Business

Attackers Exploit Critical Check Point Bug to Hijack Firewall Mgmt

Attackers are actively exploiting a critical authentication bypass vulnerability (CVE-2026-16232) in Check Point Security Management and Multi-Domain Security Management servers,…

Read More »
BigTech Companies

CISA integrates its vulnerability disclosure lessons into new guidance

CISA and allied cyber authorities released new guidance for software vendors on establishing coordinated vulnerability disclosure (CVD) programs, emphasizing transparent…

Read More »
Artificial Intelligence

Microsoft Warns of Rising Number of Security Updates

Microsoft warns that AI-powered security analysis will significantly increase the volume of Windows security updates, as AI helps identify more…

Read More »
AI & Tech

CISA orders agencies to patch critical Langflow flaw

CISA has ordered all federal agencies to patch a critical Langflow vulnerability (CVE-2025-XXXX) by Friday, as it is being actively…

Read More »
Business

Critical Adobe ColdFusion bug exploited in active attacks

Attackers are actively exploiting a critical Adobe ColdFusion vulnerability, CVE-2026-48282, which allows unauthenticated remote code execution on unpatched versions 2025.9,…

Read More »
Business

CISA warns of critical Ubiquiti flaws exploited in attacks

CISA has added three Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) to its Known Exploited Vulnerabilities catalog, which can be…

Read More »
Business

CISA Urges Fortinet Users to Patch After FortiBleed Leak

CISA has urgently called for Fortinet users to secure systems after 74,000 firewall and VPN credentials were leaked in the…

Read More »
Business

CISA orders feds to patch critical Joomla bug by Friday

CISA has mandated all U.S. federal agencies patch a maximum-severity vulnerability (CVSS 10.0) in the Joomla Widget Factory JCE plugin…

Read More »