CISA KEV

Security Notices
CVE-2026-20349: Cisco ASA and FTD remote-access VPN denial of service

Affected Cisco ASA and FTD remote-access listeners can let unauthenticated attackers trigger a reload. Check SSL VPN, IKEv2 and ZTNA configuration, then install the branch-specific hardening release to address the service-disruption risk.

Read this guide
Security Notices
CVE-2026-20316: Cisco FMC static credential is exploited and ransomware-linked

A hard-coded FMC password can expose sensitive data through a low-privileged account. Restrict management access, install Cisco's current hardening release, and review indicators; the initial access is not itself root access.

Read this guide
Security Notices
CVE-2026-16812: Arista VeloCloud Orchestrator unauthenticated command injection

Command injection threatens on-premises VeloCloud Orchestrator hosts and their managed data. Restrict exposure, upgrade the orchestrator branch, and examine downstream edge state and trust material when compromise is suspected.

Read this guide
Security Notices
CVE-2026-76460: Cisco ISE authentication bypass is actively exploited

Cisco reports active exploitation of an ISE and ISE-PIC authentication bypass that can lead to root access. Check every node, preserve off-device evidence, and separate patch installation from investigation and trusted recovery.

Read this guide
Security Notices
CVE-2026-58704: Pixel cellular-modem privilege escalation

The exploited Pixel cellular-modem flaw can bypass permission checks. Install the current Pixel update, restart, and verify the security patch level; a successful update does not establish whether earlier exploitation occurred.

Read this guide
Security Notices
CVE-2026-76461: Cisco Secure Email Gateway crafted-email root command execution

Cisco Secure Email Gateway SQL injection can give unauthenticated attackers root command execution. Preserve mail and network evidence, match the AsyncOS upgrade path, and use Cisco TAC when compromise is suspected.

Read this guide
Security Notices
CVE-2026-86060: MikroTik RouterOS MikroTrick policy-mask privilege escalation

MikroTik RouterOS policy-mask manipulation can escalate privileges. Upgrade the affected release, restrict untrusted SSH access, and inspect users, scripts and configuration even when the router does not report a Flagged state.

Read this guide
Security Notices
CVE-2026-67277: MikroTik RouterOS btest unauthenticated memory disclosure and denial of service

Missing authentication in RouterOS btest can disclose kernel memory or interrupt service. Check the service and release, then install the supported fix; restricting SSH alone does not establish that this btest flaw is resolved.

Read this guide
Security Notices
CVE-2026-20079: Cisco FMC unauthenticated authentication bypass to root

Cisco FMC authentication bypass can give unauthenticated attackers root access. Restrict management exposure, preserve evidence, and follow release-specific hardening and compromise assessment; patching alone does not resolve an existing intrusion.

Read this guide
Security Notices
CVE-2026-19490: NetScaler Gateway and AAA authentication bypass

NetScaler appliances configured as Gateway or AAA virtual servers can permit unauthenticated access. Check the exact edition and build, upgrade affected customer-managed instances, and preserve evidence for the separate compromise review.

Read this guide