CISA Advisories
topic · security/cisa-advisories
§01
about
CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 113 events in this window (176 total on topic). adjust the range or clear it with ALL.
range
01CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability T{"url":"https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-e…
EVENT. cmrjj6lmID. cmrjj6lml4mhnkh0co22ukcrlSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog",
"cves": [
"CVE-2008-4128"
],
"slug": "cisa-adds-one-known-exploited-vulnerability-catalog",
"title": "CISA Adds One Known Exploited Vulnerability to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed",
"cve_count": 1,
"categories": [],
"word_count": 222,
"mentions_ics": false,
"published_at": "2026-07-13T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://edit.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2008-4128",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
],
"mentions_ransomware": false
}02CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangero{"url":"https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-e…
EVENT. cmrf8t1jID. cmrf8t1jk3iepkh0cn1vcogykSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog",
"cves": [
"CVE-2026-48939",
"CVE-2026-56291"
],
"slug": "cisa-adds-two-known-exploited-vulnerabilities-catalog",
"title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifi",
"cve_count": 2,
"categories": [],
"word_count": 236,
"mentions_ics": false,
"published_at": "2026-07-10T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2026-48939",
"https://www.cve.org/CVERecord?id=CVE-2026-56291",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
],
"mentions_ransomware": false
}03Schneider Electric Easergy MiCOM Px40 SeriesView CSAF Summary Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px4{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03","cves":[…
EVENT. cmrdr46lID. cmrdr46lz33ybkh0cb90ql4lqSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03",
"cves": [
"CVE-2026-4832"
],
"slug": "icsa-26-190-03",
"title": "Schneider Electric Easergy MiCOM Px40 Series",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol. The following versions of Schneider Electric Easergy MiCOM Px40 Series are affected: Easergy MiCOM P14x All versions prior to B4A Easergy MiCOM P24x All versions prior to D3A Easergy MiCOM P341 All versions prior to E3F Easergy MiCOM P342, P343, P344, P345 All versions prior to B3F Easerg",
"cve_count": 1,
"categories": [],
"word_count": 1575,
"mentions_ics": true,
"published_at": "2026-07-09T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-03.json",
"https://www.cve.org/CVERecord?id=CVE-2026-4832",
"https://cwe.mitre.org/data/definitions/798.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
],
"mentions_ransomware": false
}04OpenPLC v3View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution {"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01","cves":[…
EVENT. cmrdr461ID. cmrdr461733y9kh0cb2chdpu3SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01",
"cves": [
"CVE-2026-14480"
],
"slug": "icsa-26-190-01",
"title": "OpenPLC v3",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user. The following versions of OpenPLC v3 are affected: OpenPLC v3 CVSS Vendor Equipment Vulnerabilities v3 9.9 OpenPLC OpenPLC v3 External Control of File Name or Path Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-14480 OpenPLC Runtime v3 contains an authenticated arbitrary file write",
"cve_count": 1,
"categories": [],
"word_count": 624,
"mentions_ics": true,
"published_at": "2026-07-09T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-14480",
"https://cwe.mitre.org/data/definitions/73.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
],
"mentions_ransomware": false
}05Schneider Electric PowerChute Serial ShutdownView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger deni{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02","cves":[…
EVENT. cmrdr45hID. cmrdr45h433y7kh0c9qcjxfg0SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02",
"cves": [
"CVE-2026-2399",
"CVE-2026-2404",
"CVE-2026-2405",
"CVE-2026-2403",
"CVE-2026-2400",
"CVE-2026-2401",
"CVE-2026-2402"
],
"slug": "icsa-26-190-02",
"title": "Schneider Electric PowerChute Serial Shutdown",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 CVSS Vendor Equipment Vulnerabilities v3 6.1 SuSE, Schneider Electric, Red Hat, Microsoft Schneider Electric PowerChute Serial Shutdown Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Encoding or Escaping of Output, Improper Restriction of Excessive Authentication Attempts, Uncontrolled Resource Consumption,",
"cve_count": 7,
"categories": [],
"word_count": 2796,
"mentions_ics": true,
"published_at": "2026-07-09T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-02.json",
"https://www.cve.org/CVERecord?id=CVE-2026-2399",
"https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/",
"https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/",
"https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN"
],
"mentions_ransomware": false
}06CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability This {"url":"https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-e…
EVENT. cmrb4sugID. cmrb4sugb2epfkh0c657cxqw0SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog",
"cves": [
"CVE-2026-48282"
],
"slug": "cisa-adds-one-known-exploited-vulnerability-catalog",
"title": "CISA Adds One Known Exploited Vulnerability to Catalog",
"source": "cisa.gov",
"excerpt": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed ass",
"cve_count": 1,
"categories": [],
"word_count": 221,
"mentions_ics": false,
"published_at": "2026-07-07T12:00:00.000Z",
"advisory_type": "alert",
"outbound_links": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"https://www.cve.org/CVERecord?id=CVE-2026-48282",
"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
"https://www.cisa.gov/known-exploited-vulnerabilities",
"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w"
],
"mentions_ransomware": false
}07Hydro-Québec Le Circuit Electrique charging station backendView CSAF Summary Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. The following versions of Hydro-Québec Le Circuit Electr{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01","cves":[…
EVENT. cmraye3oID. cmraye3oo2cqdkh0cokmsdulsSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01",
"cves": [
"CVE-2026-20744",
"CVE-2026-42952",
"CVE-2026-44383"
],
"slug": "icsa-26-188-01",
"title": "Hydro-Québec Le Circuit Electrique charging station backend",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected: Le Circuit Electrique charging station backend CVSS Vendor Equipment Vulnerabilities v3 9.8 Hydro-Québec Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Canada Company Headquarters Location: Canada Vulnerabilities Expand All + CVE-2026-20744 The charging station websocket endpoint accepts connections without proper authentication, wh",
"cve_count": 3,
"categories": [],
"word_count": 715,
"mentions_ics": true,
"published_at": "2026-07-07T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json",
"https://www.cve.org/CVERecord?id=CVE-2026-20744",
"https://cwe.mitre.org/data/definitions/284.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
],
"mentions_ransomware": false
}08Siemens Mendix Studio ProView CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during th{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04","cves":[…
EVENT. cmraye2yID. cmraye2yt2cq9kh0caslmum36SRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04",
"cves": [
"CVE-2026-48192"
],
"slug": "icsa-26-188-04",
"title": "Siemens Mendix Studio Pro",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Mendix Studio Pro are affected: Mendix Studio Pro 10.11 vers:all/* Mendix Studio Pro 10.12 vers:all/* Mendix Studio Pro 10.13 vers:all/* Mendix Studio Pro 10.14 vers:all/* Mendix Studio Pro 10.15 vers:all/*&nbs",
"cve_count": 1,
"categories": [],
"word_count": 955,
"mentions_ics": true,
"published_at": "2026-07-07T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-04.json",
"https://www.cve.org/CVERecord?id=CVE-2026-48192",
"https://docs.mendix.com/releasenotes/studio-pro/10.24/",
"https://docs.mendix.com/releasenotes/studio-pro/11.6/",
"https://cwe.mitre.org/data/definitions/94.html"
],
"mentions_ransomware": false
}09Siemens SINEC OSView CSAF Summary SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. The following versio{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05","cves":[…
EVENT. cmraye2fID. cmraye2f42cq7kh0cz4b5ynneSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05",
"cves": [
"CVE-2025-1352",
"CVE-2025-1376",
"CVE-2025-6052",
"CVE-2025-6141",
"CVE-2025-6170",
"CVE-2025-7039",
"CVE-2025-8732",
"CVE-2025-9086",
"CVE-2025-9230",
"CVE-2025-9231",
"CVE-2025-9232",
"CVE-2025-10966",
"CVE-2025-13465",
"CVE-2025-13601",
"CVE-2025-39913",
"CVE-2025-40214",
"CVE-2025-40248",
"CVE-2025-40250",
"CVE-2025-40251",
"CVE-2025-40252",
"CVE-2025-40254",
"CVE-2025-40257",
"CVE-2025-40258",
"CVE-2025-40261",
"CVE-2025-40262",
"CVE-2025-40263",
"CVE-2025-40264",
"CVE-2025-40271",
"CVE-2025-40278",
"CVE-2025-40280",
"CVE-2025-40281",
"CVE-2025-40345",
"CVE-2025-46394",
"CVE-2025-49794",
"CVE-2025-49795",
"CVE-2025-49796",
"CVE-2025-60876",
"CVE-2025-66035",
"CVE-2025-66382",
"CVE-2025-66412",
"CVE-2025-69720",
"CVE-2025-71185",
"CVE-2025-71186",
"CVE-2025-71188",
"CVE-2025-71189",
"CVE-2025-71190",
"CVE-2025-71191",
"CVE-2026-1484",
"CVE-2026-1489",
"CVE-2026-3784",
"CVE-2026-22610",
"CVE-2026-22976",
"CVE-2026-22977",
"CVE-2026-23025",
"CVE-2026-23026",
"CVE-2026-23030",
"CVE-2026-23031",
"CVE-2026-23032",
"CVE-2026-23033",
"CVE-2026-23037",
"CVE-2026-23038",
"CVE-2026-23111",
"CVE-2026-23112",
"CVE-2026-23220",
"CVE-2026-23222",
"CVE-2026-23228",
"CVE-2026-23229",
"CVE-2026-23230",
"CVE-2026-23231",
"CVE-2026-23236",
"CVE-2026-23238",
"CVE-2026-24515",
"CVE-2026-25210",
"CVE-2026-26157",
"CVE-2026-26158",
"CVE-2026-35535",
"CVE-2026-41918"
],
"slug": "icsa-26-188-05",
"title": "Siemens SINEC OS",
"source": "cisa.gov",
"excerpt": "View CSAF Summary SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. The following versions of Siemens SINEC OS are affected: RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/<4.0 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SINEC OS Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Stack-based Buffer Overflow, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Uncontrolled Recursion, Out-of-bounds Read, Covert Timing Channel, Improper Input Validation, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Polluti",
"cve_count": 77,
"categories": [],
"word_count": 13882,
"mentions_ics": true,
"published_at": "2026-07-07T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-05.json",
"https://www.cve.org/CVERecord?id=CVE-2025-1352",
"https://support.industry.siemens.com/cs/ww/en/view/110002573/",
"https://cwe.mitre.org/data/definitions/119.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
],
"mentions_ransomware": false
}10Digi International PortServer TS, Digi One SP IAView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious sc{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07","cves":[…
EVENT. cmraye1vID. cmraye1v52cq5kh0cyobsprgoSRC. key:cmpxakb6…
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07",
"cves": [
"CVE-2026-12352",
"CVE-2026-12948"
],
"slug": "icsa-26-188-07",
"title": "Digi International PortServer TS, Digi One SP IA",
"source": "cisa.gov",
"excerpt": "View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected: PortServer TS Digi One SP Digi One SP IA Digi One IA CVSS Vendor Equipment Vulnerabilities v3 5.9 Digi International Digi International PortServer TS, Digi One SP IA Incorrect Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Information Technology, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities ",
"cve_count": 2,
"categories": [],
"word_count": 962,
"mentions_ics": true,
"published_at": "2026-07-07T12:00:00.000Z",
"advisory_type": "ics_advisory",
"outbound_links": [
"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-07.json",
"https://www.cve.org/CVERecord?id=CVE-2026-12352",
"https://www.digi.com/support",
"https://cwe.mitre.org/data/definitions/863.html",
"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
],
"mentions_ransomware": false
}showing 1–10 of 113older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above