Current threats. Clear scope. Direct vendor guidance.

The TechGeeks Security Notice Center turns authoritative vendor and government disclosures into concise operator guidance. Each CVE has a stable issue page with applicability, priority, remediation boundaries, investigation notes, and direct primary-source links.

Browse all Security Notices · Subscribe to the Security Notices feed

Quick Answer

Start with confirmed exploitation, then vendor severity and exposed management-plane risk. Match the exact product, platform, release, feature, and exposure against the live advisory; preserve relevant off-device evidence; apply the vendor-directed fix; and validate service and security behavior. Keep severity, exploitation, ransomware association, and forensic-triage status separate. Patching closes a documented flaw but does not prove an exposed system was never compromised.

Last verified: September 17, 2026 UTC. CISA and vendor status can change; each issue page links the live advisory that controls affected and fixed release information.

Context

Coverage At A Glance

CVSS means Common Vulnerability Scoring System, a standard numeric measure of technical severity. It helps compare potential impact, but it does not tell you whether attackers are using a flaw.

182
CVE issue pages
103
CISA KEV notices
46
Critical CVSS
49
High CVSS
38
Medium CVSS
1
Low CVSS
48
CVSS not captured

The center contains 182 canonical CVE pages spanning Microsoft, Apple, Android and mobile components, network infrastructure, security platforms, and related enterprise technologies. Of those, 103 carry CISA Known Exploited Vulnerabilities evidence. Each CVE is counted once, even when multiple primary sources or vendor publications cover it.

Severity cards use published numeric CVSS base scores captured in the cited records: 46 Critical, 49 High, 38 Medium, and 1 Low. A further 48 notices are labeled CVSS not captured because a numeric score was not safely preserved in the research record. TechGeeks does not infer a score from CISA KEV status, a vendor label, or exploit evidence; those signals remain separate on each issue page.

Priority Highlights Across Vendors

This cross-vendor selection highlights confirmed exploitation, privilege, management-plane exposure, and severe impact across major operating-system, mobile, network, and security ecosystems. It is a starting point rather than a complete ranking; the searchable index covers every notice. TechGeeks priority tiers support triage and are not universal legal deadlines.

P0 — ACT NOWCISA KEVMICROSOFT

CVE-2026-81963: Windows Update Stack privilege escalation to SYSTEM

Microsoft — Windows
CISA KEV added 2026-09-08; vendor and CISA details are separated on the issue page.

Install the applicable September 2026 or later Windows cumulative update and verify the resulting Windows build against the live MSRC table.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVAPPLE

CVE-2026-65400: macOS Screen Sharing authentication bypass

Apple — macOS
CISA KEV added 2026-08-18; vendor and CISA details are separated on the issue page.

Update every affected Mac to the newest supported macOS release; the minimum Apple-fixed branches are Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVGOOGLE

CVE-2026-58704: Pixel cellular-modem privilege escalation

Google — Pixel
CISA KEV added 2026-09-16; vendor and CISA details are separated on the issue page.

Install the current Pixel system update, restart the device, and verify that Android security update is 2026-09-05 or later.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVCISCO

CVE-2026-76460: Cisco ISE authentication bypass is actively exploited

Cisco — Identity Services Engine
CISA KEV added 2026-09-16; vendor and CISA details are separated on the issue page.

Restrict ISE management and control-plane access, preserve off-device evidence, review every deployment node, and upgrade to the fixed patch for the installed train. If malicious activity is suspected, follow Cisco TAC guidance and re-image affected nodes rather than treating patching as eradication.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVFORTINET

CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet — Multiple Products
CISA KEV added 2026-09-09; vendor and CISA details are separated on the issue page.

Confirm the exact product, release, exposure, and prerequisites against the live vendor advisory, then apply the vendor-listed update or mitigation. CISA added CVE-2025-25249 to KEV on 2026-09-09.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVCHECK POINT

CVE-2026-50751: Check Point deprecated IKEv1 VPN authentication bypass

Check Point — Security Gateway
CISA KEV added 2026-06-08; vendor and CISA details are separated on the issue page.

Install the Check Point hotfix or disable deprecated IKEv1, then review VPN sessions, accounts, certificates, and gateway evidence.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVARISTA

CVE-2026-16812: Arista VeloCloud Orchestrator unauthenticated command injection

Arista — VeloCloud Orchestrator
CISA KEV added 2026-07-27; vendor and CISA details are separated on the issue page.

Restrict orchestrator exposure, preserve evidence and configuration, and upgrade the VCO branch to an advisory-listed fixed release. Review downstream managed-edge state and trust material if compromise is suspected.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVUBIQUITI

CVE-2026-34910: UniFi OS input-validation flaw

Ubiquiti — UniFi OS
CISA KEV added 2026-06-23; vendor and CISA details are separated on the issue page.

Update every affected UniFi OS console or server to the product-specific fixed release in SAB-064 and review system and access logs for unexplained activity.

Open TechGeeks notice · Vendor notice

P0 — ACT NOWCISA KEVHEWLETT PACKARD ENTERPRISE (HPE)

CVE-2025-37164: HPE OneView unauthenticated remote code execution

Hewlett Packard Enterprise (HPE) — OneView
CISA KEV added 2026-01-07; vendor and CISA details are separated on the issue page.

Confirm the exact OneView version and apply the HPE bulletin's fixed release or mitigation. Restrict management access until remediation is complete.

Open TechGeeks notice · Vendor notice

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20130: Cisco ISE hardening: Improper Neutralization Vulnerabilities

Cisco Identity Services Engine (ISE)
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 10 (Critical). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Open TechGeeks notice · Cisco advisory

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTED

CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Execution Vulnerability

Cisco Secure Firewall Management Center (FMC)
Cisco advisory SIR: Critical; CVE-specific SIR: Not separately stated; CVSS base: 9.9 (Critical). Cisco reported no public announcement or malicious use for this CVE at the last check.

Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release. The CVE-specific live advisory and Cisco Software Checker result control the First Fixed release; any combined hardening baseline is supplemental only.

Open TechGeeks notice · Cisco advisory

All Security Notices

Every CVE below has one canonical page. The groups keep confirmed exploitation separate from vendor severity and from the materially revised older advisory.

Find a Security Notice

Filter the complete issue index by vendor, technology, response tier, or CVE and keyword.

Showing 182 of 182 notices

No notices match those filters. Reset one or more fields and try again.

Microsoft — CISA KEV — 38 notices
Apple / macOS / iPhone / iPad — CISA KEV — 8 notices
Android / Pixel / components — CISA KEV — 4 notices
Network and edge vendors — CISA KEV — 53 notices
Cisco PSIRT — Critical / High advisory SIR — 54 notices
Cisco PSIRT — Medium advisory SIR — 24 notices
Cisco PSIRT — materially revised older advisory — 1 notices

Steps

If Your Product Matches

  1. Confirm: record the exact product, hardware or virtual platform, release, patch level, enabled feature, role, exposure, and advisory revision.
  2. Contain: restrict unnecessary management, VPN, portal, API, messaging, or service exposure using supported controls.
  3. Preserve: save external logs, accounts, sessions, configuration, and UTC context before evidence rotates.
  4. Prepare: verify off-device backups, console or out-of-band access, credentials, certificates, licenses, capacity, and the supported upgrade path.
  5. Remediate and validate: apply the vendor action, confirm the resulting version, then test service health, expected access, expected denial, dependencies, logging, failover, and monitoring.
  6. Investigate and recover: when exposure or evidence creates doubt, move from patch management to incident response and trusted recovery.

Notes

How To Read The Signals

  • P0 — Act now: TechGeeks operational priority for confirmed exploitation. It is not a CVSS score or universal legal deadline.
  • P1 — Urgent: Critical or High Cisco advisory SIR, or another urgent vendor impact, requiring prompt exact-match review and vendor-directed remediation.
  • P2 — Review: Medium Cisco advisory SIR, or another review-tier vendor impact, that still requires applicability, exposure, and compensating-control review.
  • CISA KEV: CISA has evidence the CVE was exploited; this does not state prevalence or prove a particular asset was compromised.
  • Advisory SIR / CVE SIR / CVSS: separate vendor impact and scoring signals supplied by Cisco; none establishes exploitation by itself.
  • Vendor 'not aware' wording: a time-bounded status statement, not proof of no exploitation.

Validation And Boundaries

This center is documentation-backed and does not replace vendor advisory databases, asset inventory, a vulnerability-management platform, or incident response. A KEV entry does not prove mass exploitation. A Critical rating does not prove exploitation. A clean indicator search does not prove a privileged attacker was absent. A successful update does not prove persistence was removed or every workflow is healthy. TechGeeks did not reproduce these exploits or independently test every patch.

Related TechGeeks Resources

References

Wrap-Up

Subscribe to the Security Notices feed, record exact product matches in your vulnerability queue, and assign owners by evidence and exposure. Open the linked vendor advisory immediately before each change because affected releases, fixed builds, and exploitation statements can be revised.

Correction policy: Material source changes trigger an issue-page update, an index reconciliation, and a new reader-visible verification date.