CISA KEV

Security Notices
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Unauthenticated SD-WAN Manager API requests can expose sensitive operating-system information. This CVE does not inherit neighboring flaws' root or overwrite impacts, nor their release exclusions; preserve API evidence and use the disclosure-specific fix guidance.

Read this guide
Security Notices
CVE-2026-7473: Arista EOS tunnel decapsulation validation flaw

Affected Arista EOS switches can forward unexpected tunnel traffic sent to a configured decapsulation IP. Arista specifies ACL mitigation, not a software upgrade; plan filters around shared-IP services and potentially disruptive TCAM changes.

Read this guide
Security Notices
CVE-2026-20245: Cisco Catalyst SD-WAN authenticated root privilege escalation

An attacker with netadmin privileges can use a crafted file to gain root on affected SD-WAN control components. Preserve admin-tech before upgrading, then inspect indicators and verify downstream edge-device configuration.

Read this guide
Security Notices
CVE-2026-50751: Check Point deprecated IKEv1 VPN authentication bypass

Check Point's exploited VPN bypass requires Remote Access or Mobile Access, IKEv1, accepted legacy clients and no mandatory machine certificate. Gateway and Spark remediation differ; review suspicious VPN sessions separately from installing the appropriate fix.

Read this guide
Security Notices
CVE-2025-48595: Android Framework privilege escalation

Android Framework integer overflow can enable local privilege escalation beyond normal device permissions. Install the OEM security update and verify its reported patch level; this platform issue is not limited to Pixel devices.

Read this guide
Security Notices
CVE-2026-0257: PAN-OS GlobalProtect authentication bypass

GlobalProtect authentication-override cookies can permit unauthorized VPN connections under the affected certificate configuration. Coordinate fixes across every cookie-generating and accepting portal or gateway, including hybrid Prisma Access deployments, and investigate sessions separately from patching.

Read this guide
Security Notices
CVE-2026-45498: Microsoft Defender local denial of service

The exploited Microsoft Defender flaw can interrupt protection through denial of service. Verify the Antimalware Platform update on each endpoint and examine Defender health telemetry; a currently healthy service does not rule out earlier disruption.

Read this guide
Security Notices
CVE-2026-41091: Microsoft Malware Protection Engine privilege escalation

A link-following flaw in Microsoft Malware Protection Engine can let an authorized local attacker gain SYSTEM privileges. Verify the installed engine update and review endpoint telemetry; this is not unauthenticated remote takeover.

Read this guide
Security Notices
CVE-2010-0806: Legacy Internet Explorer use-after-free RCE

Crafted content viewed in affected legacy Internet Explorer versions can run code with the user's rights. MS10-018 documents the historical fix; it does not restore support, so surviving unsupported browser and platform combinations require retirement.

Read this guide
Security Notices
CVE-2010-0249: Legacy Internet Explorer use-after-free RCE

CVE-2010-0249 can execute code through crafted web content in legacy Internet Explorer. Microsoft's original bulletin reported limited attacks; the 2026 KEV addition is separate history, not a new disclosure or justification for retaining unsupported systems.

Read this guide