SecNoteMorning brief
Latest sync Aug 28, 10:22 PM
1 down

Reading Queue

Help
TodayActionsStack WatchFeedIntelligence
More
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Queue triage

All feed: 27 matches for "CISA"

Top item: CISA Adds Six Known Exploited Vulnerabilities to Catalog

Action filterAll items
Showing18Saved0Sources down1

Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.

Reading Queue

Showing 18 of 27 visible rows.

Current state
More filters
criticalVulnerabilityKnown exploitedActive exploit

CVE-2015-3246 — Red Hat Libuser Race Condition +5 more (CISA KEV)

CISA Advisories | Aug 26, 2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabili...

Evidence and analyst toolsscore 124
Sourcerss | ok | CISA Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 PM UTC
Score inputsbase score 124, priority score 134, critical severity, 6 CVEs, CISA Advisories feed item, Mentions CVE-2015-3246, CVE-2015-5287, Watchlist: CISA, KEV, Microsoft, Known exploited, Active exploit, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#Microsoft#Citrix#Linux
Sigma searchNuclei searchSentinel search
criticalVulnerabilityKnown exploitedActive exploit

CVE-2023-49105 — ownCloud Improper Authentication +2 more (CISA KEV)

CISA Advisories | Aug 27, 2026

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCloud Improper Authentication Vulnerability CVE-2026-53362 Linux Kernel Unspecified Vulnerability CVE-2026-66384 JFrog Art...

Evidence and analyst toolsscore 120
Sourcerss | ok | CISA Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 12:00 PM UTC
Score inputsbase score 120, priority score 130, critical severity, 3 CVEs, CISA Advisories feed item, Mentions CVE-2023-49105, CVE-2026-53362, Watchlist: CISA, KEV, Linux, Known exploited, Active exploit
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#Linux#CVE-2023-49105#CVE-2026-53362
Sigma searchNuclei searchSentinel search
criticalVulnerabilityKnown exploitedActive exploit

CVE-2026-60004 — Gitea Code Injection (CISA KEV)

CISA Advisories | Aug 25, 2026

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses si...

Evidence and analyst toolsscore 114
Sourcerss | ok | CISA Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 25, 2026, 12:00 PM UTC
Score inputsbase score 114, priority score 114, critical severity, 1 CVE, CISA Advisories feed item, Mentions CVE-2026-60004, Watchlist: CISA, KEV, Known exploited, Active exploit
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#CVE-2026-60004#CISA Advisories
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

SecurityWeek | Aug 28, 2026

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.

Evidence and analyst toolsscore 104
Sourcerss | ok | SecurityWeek
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 12:36 PM UTC
Score inputsbase score 104, priority score 122, high severity, 1 CVE, SecurityWeek feed item, AI relevance match, Mentions CVE-2026-53362, Known exploited
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#Linux#OpenAI#CVE-2026-53362
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-66384: JFrog Artifactory - JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

CISA KEV | Aug 27, 2026

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

Evidence and analyst toolsscore 86
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 12:00 AM UTC
Score inputsbase score 86, priority score 96, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: JFrog, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#JFrog#Artifactory
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2021-23758: Ajax.NET Professional Ajax.NET Professional - Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

CISA KEV | Aug 26, 2026

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue us...

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Ajax.NET Professional, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Ajax.NET Professional
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2015-5287: Red Hat Automatic Bug Reporting Tool - Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

CISA KEV | Aug 26, 2026

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or ...

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Red Hat, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Red Hat#Automatic Bug Reporting Tool
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2022-0995: Linux Kernel - Linux Kernel Out-of-Bounds Write Vulnerability

CISA KEV | Aug 26, 2026

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Linux, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Linux#Kernel
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway - Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

CISA KEV | Aug 26, 2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Citrix, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Citrix#NetScaler ADC and NetScaler Gateway
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2019-1068: Microsoft SQL Server - Microsoft SQL Server Remote Code Execution Vulnerability

CISA KEV | Aug 26, 2026

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#SQL Server
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in - Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

CISA KEV | Aug 24, 2026

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Ora...

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 24, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 52, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Oracle, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Oracle#HTTP Server and Oracle Weblogic Server Proxy Plug-in
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS) - Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

CISA KEV | Aug 21, 2026

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 21, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 40, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Synacor, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Synacor#Zimbra Collaboration Suite (ZCS)
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-72530: TrueConf Server - TrueConf Server Code Injection Vulnerability

CISA KEV | Aug 20, 2026

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 20, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 39, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: TrueConf, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#TrueConf#Server
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-72529: TrueConf Server - TrueConf Server Missing Authentication for Critical Function Vulnerability

CISA KEV | Aug 20, 2026

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 20, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 39, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: TrueConf, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#TrueConf#Server
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-64849: MLflow MLflow - MLflow Server-Side Request Forgery Vulnerability

CISA KEV | Aug 19, 2026

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 19, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 37, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: MLflow, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#MLflow
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions - Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

CISA KEV | Aug 18, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 18, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 36, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#Internet Key Exchange (IKE) Service Extensions
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-59310: Broadcom VMware vCenter - Broadcom VMware vCenter Path Traversal Vulnerability

CISA KEV | Aug 18, 2026

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 18, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 36, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Broadcom, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Broadcom#VMware vCenter
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-55040: Microsoft SharePoint - Microsoft SharePoint Weak Authentication Vulnerability

CISA KEV | Aug 18, 2026

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 18, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 36, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#SharePoint
Sigma searchNuclei searchSentinel search
TrustSource health1 failed and 4 degraded sources in this run.

Source Health

69 sources
Coverage impact: failed: GDELT. degraded: NPR Politics, Defense.gov News, Federal Reserve Press, GovInfo Federal Register. Treat affected lanes as incomplete until refresh succeeds.

BleepingComputer

rss | 15 items

ok

The Hacker News

rss | 18 items

ok

SecurityWeek

rss | 10 items

ok

Dark Reading

rss | 18 items

ok

KrebsOnSecurity

rss | 10 items

ok

OpenAI News

rss | 8 items

ok

TechCrunch AI

rss | 10 items

ok

VentureBeat AI

rss | 7 items

ok

The Verge AI

rss | 8 items

ok

Google AI

rss | 10 items

ok

MIT News AI

rss | 8 items

ok

MIT Technology Review

rss | 6 items

ok

The Register AI/ML

rss | 8 items

ok

Google Project Zero

rss | 7 items

ok

CISA Advisories

rss | 18 items

ok

CISA ICS Advisories

rss | 8 items

ok

Microsoft Security

rss | 8 items

ok

Microsoft MSRC Updates

rss | 10 items

ok

Cisco Security Advisories

rss | 8 items

ok

Palo Alto Security Advisories

rss | 8 items

ok

FortiGuard Outbreak Alerts

rss | 8 items

ok

FortiGuard Threat Signal

rss | 8 items

ok

Chrome Releases

rss | 8 items

ok

Mozilla Security

rss | 8 items

ok

Unit 42

rss | 8 items

ok

Cisco Talos

rss | 8 items

ok

ESET WeLiveSecurity

rss | 8 items

ok

Malwarebytes Labs

rss | 8 items

ok

SentinelOne

rss | 6 items

ok

SANS Internet Storm Center

rss | 8 items

ok

CrowdStrike

rss | 7 items

ok

CyberScoop

rss | 8 items

ok

The Record

rss | 5 items

ok

DataBreaches.net

rss | 6 items

ok

BBC World

rss | 7 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 3 items

ok

NPR Politics

rss | 0 items | Source responded but no relevant items matched.

degraded

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian US Politics

rss | 5 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Politics

rss | 3 items

ok

Defense.gov News

rss | 0 items | Source responded but no relevant items matched.

degraded

Federal Reserve Press

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Federal Register

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Congressional Bills

rss | 6 items

ok

NPR News

rss | 8 items

ok

NPR National

rss | 8 items

ok

NPR Politics

rss | 6 items

ok

NYTimes U.S.

rss | 6 items

ok

NYTimes Politics

rss | 6 items

ok

The Guardian U.S.

rss | 6 items

ok

BBC U.S. & Canada

rss | 6 items

ok

BBC World

rss | 8 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 8 items

ok

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Business

rss | 6 items

ok

CISA KEV

structured | 22 items

ok

GitHub Advisories

api | 24 items

ok

NVD Recent CVEs

api | 18 items

ok

FIRST EPSS

api | 20 items

ok

Hacker News

api | 5 items

ok

GDELT

api | 0 items | fetch failed

failed

1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.

ScopeWatchlist75 terms used to highlight recurring products, tactics, and security topics.

Watchlist

CISAKEVzero-dayransomwareregulationtarifftradeexport controlsupply chaininitial accessidentityphishingAI securityprompt injectionmodel poisoningagentic AIdeepfakeMicrosoftWindowsAzureEntraActive DirectoryOktaCiscoPalo AltoFortinetIvantiVMware