CISA KEV

Security Notices
CVE-2026-15410: SonicWall SMA1000 administrator code injection

This SMA1000 code-injection flaw requires administrator access to the Appliance Management Console. Apply the current supported hotfix and investigate suspected compromise; the historical minimum build does not establish protection against later vulnerabilities.

Read this guide
Security Notices
CVE-2026-15409: SonicWall SMA1000 unauthenticated WorkPlace SSRF

Unauthenticated requests can make the SMA1000 WorkPlace interface contact unintended destinations. Verify the appliance model and hotfix, update, and conduct the compromise review; SonicWall firewall SSL-VPN and SMA 100 are outside this notice's scope.

Read this guide
Security Notices
CVE-2026-20316: Cisco FMC static credential is exploited and ransomware-linked

A hard-coded FMC password can expose sensitive data through a low-privileged account. Restrict management access, install Cisco's current hardening release, and review indicators; the initial access is not itself root access.

Read this guide
Security Notices
CVE-2026-16812: Arista VeloCloud Orchestrator unauthenticated command injection

Command injection threatens on-premises VeloCloud Orchestrator hosts and their managed data. Restrict exposure, upgrade the orchestrator branch, and examine downstream edge state and trust material when compromise is suspected.

Read this guide
Security Notices
CVE-2026-83549: SonicWall SMA1000 administrator command injection and RCE

SonicWall SMA1000 administrators can exploit command injection through the Appliance Management Console. Apply the supported hotfix and request a support-led compromise review; this is distinct from the separate unauthenticated WorkPlace flaw.

Read this guide
Security Notices
CVE-2026-83548: SonicWall SMA1000 pre-authentication SSRF and proxy bypass

An unintended SMA1000 WorkPlace proxy path can expose sensitive functionality without authentication. Install SonicWall's supported hotfix, preserve exposure history, and obtain a support-led indicator review rather than treating the update as proof of recovery.

Read this guide
Security Notices
CVE-2026-8452: NetScaler memory-bounds flaw can cause denial of service

NetScaler memory-boundary failures can interrupt ADC or Gateway service. Match the appliance edition, configuration and build to the fixed release; this CVE does not establish authentication bypass or code execution.

Read this guide
Security Notices
CVE-2019-1068: SQL Server remote code execution

An authenticated attacker can use a crafted SQL query to execute code as the SQL Server Database Engine service account. Match the service pack and GDR or CU branch; CISA now lists the flaw as exploited.

Read this guide
Security Notices
CVE-2026-65400: macOS Screen Sharing authentication bypass

The macOS Screen Sharing flaw can let a network attacker authenticate without valid credentials. Check service reachability and the installed macOS branch, apply its supported update, and preserve relevant authentication evidence.

Read this guide
Security Notices
CVE-2026-55040: SharePoint authentication bypass

SharePoint's authentication bypass can permit unauthenticated user impersonation. CISA's later exploitation listing differs from Microsoft's original assessment; update every affected on-premises farm server and preserve web, authentication and audit evidence.

Read this guide