Cisa
12 articles
Advertisement
Articles12
The Most Exploited Flaw Classes Were All Solved Decades Ago
Improper input validation, path traversal and command injection top the list of what attackers actually use. A...
KE
31 Aug
CISA Listed Two Flaws as Exploited. The Attacker Was OpenAI's Own Agent.
An agent noticed the kernel under its container was vulnerable, fetched a public exploit, adapted it and took...
KE
29 Aug
Three Days to Patch. CISA's Deadline Used to Be Three Weeks.
Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measu...
KE
11 Aug
Every Flaw CISA Listed This Week Was a Tool That Builds or Runs Other Software
Five KEV listings in three days: an RMM console, a CI/CD server, a Tomcat cluster channel and an AI workflow b...
KE
6 Aug
Three Days to Patch N-able. A Year Ago 92% of KEV Entries Got Three Weeks
CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediat...
CY
4 Aug
Vulnerability Disclosures Will Pass Last Year's Record by August. The Share Anyone Actually Exploits Is Falling
AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilit...
CY
1 Aug
Four SharePoint Flaws Entered CISA's Catalogue in Twenty-Two Days — One Left a Single Working Day
CVE-2026-50522 was exploited hours after proof-of-concept code appeared, and stolen machine keys survive the p...
CY
29 Jul
CISA's Patch Deadlines Collapsed From 21 Days to Three — and It Started Four Months Before the Directive That Gets the Credit
We measured every deadline in the KEV catalog's 1,653 entries. The 21-day window was retired on 5 March; BOD 2...
CY
26 Jul
Langflow Becomes the First AI-Agent Platform on CISA's Exploited-Vulnerability List
On 7 July 2026, CISA added an actively-exploited vulnerability in Langflow — a popular open-source framework f...
CY
9 Jul
CISA orders agencies to patch an actively exploited Palo Alto firewall flaw by 1 June
Attackers are exploiting a flaw in Palo Alto Networks' PAN-OS that lets them slip past security controls and o...
CY
1 Jun
LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation
CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA...
CY
1 Jun
Critical Palo Alto Firewall Zero-Day Actively Exploited by State-Sponsored Hackers — CISA Orders Patch by 9 May
CVE-2026-0300, a critical PAN-OS buffer overflow enabling unauthenticated root-level RCE, is being actively ex...
CY
8 May
Advertisement