Cisa-Kev
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)
CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.
Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE
CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.
CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation
A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.
CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV
Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data — CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
CVE-2026-16232: Check Point SmartConsole Auth Bypass Grants Full Admin — Actively Exploited, Added to CISA KEV
An unauthenticated attacker can steal a SmartConsole application login token and log into Check Point's Security Management Server with full admin rights. CVE-2026-16232 (CVSS 9.3) is under active exploitation and now sits in CISA's KEV catalog with a July 25 remediation deadline.
CVE-2026-50522: SharePoint RCE Under Active Exploitation, Attackers Stealing Machine Keys for Post-Patch Persistence
CVE-2026-50522, a critical 9.8 CVSS SharePoint deserialization RCE, is being actively exploited to steal machine keys that let attackers forge auth tokens and keep access even after the box is patched.
ServiceNow AI Platform Sandbox-Escape RCE (CVE-2026-6875) Under Active Exploitation
A pre-authentication sandbox-escape flaw in ServiceNow's AI Platform is being exploited in the wild against unpatched instances, with attackers reaching the same code-execution primitive through a gadget chain that diverges from the published proof-of-concept.
Six Bulletins, One Bug Class: What Ubiquiti's 2026 UniFi Cadence Reveals About Shared-OS Edge Platforms
Since October 2025, Ubiquiti has shipped six security bulletins covering the UniFi line — five of them containing CVSS 9.9-10.0 flaws, two of them the exact same shell-injection bug class shipped seven months apart. This is what happens when one Nginx gateway and one OS layer sit in front of your network, your cameras, and your door locks.
AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug
A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17
Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.
Langflow Hit With Its Second CISA KEV Entry in Four Months: CVE-2026-55255 IDOR Under Active Exploitation
CISA adds Langflow CVE-2026-55255, an IDOR letting authenticated attackers hijack other users' AI workflows, to its KEV catalog after Sysdig caught in-the-wild exploitation chained with secret harvesting.
Ubiquiti's Bulletin 066: A CVSS 10.0 in UniFi Connect Leads 25 Flaws Across the Whole UniFi Line
Ubiquiti Security Advisory Bulletin 066 discloses 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and UniFi OS — headlined by CVE-2026-50746, a CVSS 10.0 unauthenticated command injection reachable on ~100,000 internet-facing endpoints.
SimpleHelp OIDC Auth Bypass (CVE-2026-48558) Under Active Exploitation, Deploying Djinn Stealer Against Dev Credentials
A critical unsigned-token flaw in SimpleHelp RMM's OIDC login is being exploited to plant a cross-platform infostealer that hunts for cloud, source-control, and AI-assistant credentials.
JADEPUFFER: First Documented Ransomware Attack Run End-to-End by an AI Agent
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited a year-old Langflow RCE (CVE-2025-3248) to breach, pivot, and encrypt a production database with zero human operator input.
Ubiquiti UniFi OS Server Triple-CVE Chain Enables Unauthenticated Root RCE
Three max-severity CVEs (2026-34908/09/10) in UniFi OS Server chain from an Nginx auth bypass to root command injection — CISA added all three to KEV on June 23 amid Mirai/Gaafgyt botnet exploitation.
CVE-2026-12569: PTC Windchill/FlexPLM Deserialization RCE Exploited in Wild, CISA Deadline Today
A critical unauthenticated deserialization RCE in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) is being actively exploited with JSP web shells; CISA federal patch deadline is today.
Arista EOS CVE-2026-7473: Tunnel Decap Flaw Bypasses Segmentation — and Arista Won't Patch It
CVE-2026-7473 lets an unauthenticated attacker push arbitrary tunneled traffic through Arista data-center switches that decapsulate it without checking the protocol. Exploited in the wild, on CISA's KEV list with a deadline of today — and Arista has confirmed no patch is coming.
LiteSpeed cPanel Plugin CVE-2026-54420: A Symlink Trick That Escapes CageFS for Root
An actively-exploited symlink flaw in LiteSpeed's user-end cPanel plugin lets any tenant with FTP or web-shell access break out of CageFS and become root. CISA's federal patch deadline is today.