CISA Advisories

topic · security/cisa-advisories
DOC.
security/cisa-advisories
REV.
176 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

CISA cybersecurity alerts, ICS advisories, and analysis reports (separate stream from KEV).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 122 events in this window (176 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorizat{"url":"https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-e…
EVENT. cmrmg6j4ID. cmrmg6j495ewdkh0csm8syus8SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "cves": [
    "CVE-2023-4346",
    "CVE-2026-46817"
  ],
  "slug": "cisa-adds-two-known-exploited-vulnerabilities-catalog",
  "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability   These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid r",
  "cve_count": 2,
  "categories": [],
  "word_count": 238,
  "mentions_ics": false,
  "published_at": "2026-07-15T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2023-4346",
    "https://www.cve.org/CVERecord?id=CVE-2026-46817",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
  ],
  "mentions_ransomware": false
}
02Establishing a Coordinated Vulnerability Disclosure Program to Work With Security ResearchersDeveloped by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and impl{"url":"https://www.cisa.gov/resources-tools/resources/establishing-coordinated-…
EVENT. cmrm7jslID. cmrm7jsl05cixkh0cyb4xymbiSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/resources-tools/resources/establishing-coordinated-vulnerability-disclosure-program-work-security-researchers",
  "cves": [],
  "slug": "establishing-coordinated-vulnerability-disclosure-program-work-security-researchers",
  "title": "Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers",
  "source": "cisa.gov",
  "excerpt": "Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning Common Vulnerabilities and Exposures (CVE) identifiers to reported vulnerabilities. The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program. By implementing a robust CVD program aligned with this guidance, organizations can work transparent",
  "cve_count": 0,
  "categories": [],
  "word_count": 130,
  "mentions_ics": false,
  "published_at": "2026-07-15T12:00:00.000Z",
  "advisory_type": "advisory",
  "outbound_links": [],
  "mentions_ransomware": false
}
03CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request{"url":"https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-…
EVENT. cmrl51ffID. cmrl51ffq529fkh0cbu9zmkvqSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog",
  "cves": [
    "CVE-2026-15409",
    "CVE-2026-15410",
    "CVE-2026-56155",
    "CVE-2026-56164"
  ],
  "slug": "cisa-adds-four-known-exploited-vulnerabilities-catalog",
  "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for F",
  "cve_count": 4,
  "categories": [],
  "word_count": 252,
  "mentions_ics": false,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2026-15409",
    "https://www.cve.org/CVERecord?id=CVE-2026-15410",
    "https://www.cve.org/CVERecord?id=CVE-2026-56155",
    "https://www.cve.org/CVERecord?id=CVE-2026-56164"
  ],
  "mentions_ransomware": false
}
04CISA Urges SharePoint Hardening After New ExploitationsCISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , and CVE-2026-56164 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server{"url":"https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint…
EVENT. cmrl0qjwID. cmrl0qjw850ybkh0ce0v7z67eSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations",
  "cves": [
    "CVE-2026-32201",
    "CVE-2026-45659",
    "CVE-2026-56164",
    "CVE-2026-55040",
    "CVE-2026-58644"
  ],
  "slug": "cisa-urges-sharepoint-hardening-after-new-exploitations",
  "title": "CISA Urges SharePoint Hardening After New Exploitations",
  "source": "cisa.gov",
  "excerpt": "CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , and CVE-2026-56164 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity.  Additionally, the following newly disclosed CVEs are not yet known to have been exploited, but Microsoft has ",
  "cve_count": 5,
  "categories": [],
  "word_count": 575,
  "mentions_ics": false,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://www.cve.org/CVERecord?id=CVE-2026-32201",
    "https://www.cve.org/CVERecord?id=CVE-2026-45659",
    "https://www.cve.org/CVERecord?id=CVE-2026-56164",
    "https://www.cve.org/CVERecord?id=CVE-2026-55040",
    "https://www.cve.org/CVERecord?id=CVE-2026-58644"
  ],
  "mentions_ransomware": false
}
05ABB Advant Master Online BuilderView CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01","cves":[…
EVENT. cmrkubeyID. cmrkubeyq4z6lkh0c4md1vn45SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01",
  "cves": [
    "CVE-2025-13162"
  ],
  "slug": "icsa-26-195-01",
  "title": "ABB Advant Master Online Builder",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions. The following versions of ABB Advant Master Online Builder are affected: Control Builder A <=1.4/4 (CVE-2025-13162) 800xA for Advant Master <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.2.0-1 (CVE-2025-13162, CVE-2025-13162, CVE-2025-13162, CVE-2025-13162) CVSS Vendor Equipment Vulnerabilities v3 4.4 ABB ABB Advant Master Online Builder Uncontrolled Search Path Element Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switz",
  "cve_count": 1,
  "categories": [],
  "word_count": 1345,
  "mentions_ics": true,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-01_drupal.json",
    "https://www.cve.org/CVERecord?id=CVE-2025-13162",
    "https://cwe.mitre.org/data/definitions/427.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
  ],
  "mentions_ransomware": false
}
06ABB Ability EdgeniusView CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a public{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02","cves":[…
EVENT. cmrkubefID. cmrkubef84z6jkh0c92pyksejSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02",
  "cves": [
    "CVE-2026-31431"
  ],
  "slug": "icsa-26-195-02",
  "title": "ABB Ability Edgenius",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system The following versions of ABB Ability Edgenius are affected: Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100, >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - E3100C, >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edge",
  "cve_count": 1,
  "categories": [],
  "word_count": 1204,
  "mentions_ics": true,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-02_drupal.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-31431",
    "https://cwe.mitre.org/data/definitions/669.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
  ],
  "mentions_ransomware": false
}
07Rockwell Automation 1715-AENTR EtherNet/IP AdapterView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentia{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04","cves":[…
EVENT. cmrkubdvID. cmrkubdvk4z6hkh0czb20hcjlSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04",
  "cves": [
    "CVE-2026-10577"
  ],
  "slug": "icsa-26-195-04",
  "title": "Rockwell Automation 1715-AENTR EtherNet/IP Adapter",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnerabilities v3 10 Rockwell Automation Rockwell Automation 1715-AENTR EtherNet/IP Adapter Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-10577 A security issue ex",
  "cve_count": 1,
  "categories": [],
  "word_count": 561,
  "mentions_ics": true,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-04.json",
    "https://www.cve.org/CVERecord?id=CVE-2026-10577",
    "https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight",
    "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1785.html",
    "https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html"
  ],
  "mentions_ransomware": false
}
08ABB T-MAC PlusView CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who succ{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03","cves":[…
EVENT. cmrkubdaID. cmrkubdal4z6fkh0c9zn2o4aySRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03",
  "cves": [
    "CVE-2025-14771",
    "CVE-2025-14772",
    "CVE-2025-14773",
    "CVE-2025-14774"
  ],
  "slug": "icsa-26-195-03",
  "title": "ABB T-MAC Plus",
  "source": "cisa.gov",
  "excerpt": "View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipment Vulnerabilities v3 9.9 ABB ABB T-MAC Plus Files or Directories Accessible to External Parties, Authorization Bypass Through User-Controlled Key, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/A",
  "cve_count": 4,
  "categories": [],
  "word_count": 1843,
  "mentions_ics": true,
  "published_at": "2026-07-14T12:00:00.000Z",
  "advisory_type": "ics_advisory",
  "outbound_links": [
    "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-03_drupal.json",
    "https://www.cve.org/CVERecord?id=CVE-2025-14771",
    "https://cwe.mitre.org/data/definitions/552.html",
    "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "https://www.cve.org/CVERecord?id=CVE-2025-14772"
  ],
  "mentions_ransomware": false
}
09Improve Router Hygiene to Protect Against Russian State-Sponsored TargetingRussian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue {"url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a","cv…
EVENT. cmrjj6m6ID. cmrjj6m6s4mhpkh0cycug6jr9SRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a",
  "cves": [
    "CVE-2018-0171",
    "CVE-2008-4128"
  ],
  "slug": "aa26-194a",
  "title": "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting",
  "source": "cisa.gov",
  "excerpt": "Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. [ 1 ]  This CSA is being released by the following authoring and co-sealing agencies:&",
  "cve_count": 2,
  "categories": [],
  "word_count": 2347,
  "mentions_ics": false,
  "published_at": "2026-07-13T12:00:00.000Z",
  "advisory_type": "cybersecurity_advisory",
  "outbound_links": [
    "https://www.ic3.gov/PSA/2025/PSA250820",
    "https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/0/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
    "https://attack.mitre.org/versions/v19/matrices/enterprise/",
    "https://attack.mitre.org/versions/v19/techniques/T1595/001/",
    "https://attack.mitre.org/versions/v19/techniques/T1595/002/"
  ],
  "mentions_ransomware": false
}
10CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability T{"url":"https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-e…
EVENT. cmrjj6lmID. cmrjj6lml4mhnkh0co22ukcrlSRC. key:cmpxakb6
{
  "url": "https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog",
  "cves": [
    "CVE-2008-4128"
  ],
  "slug": "cisa-adds-one-known-exploited-vulnerability-catalog",
  "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
  "source": "cisa.gov",
  "excerpt": "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed",
  "cve_count": 1,
  "categories": [],
  "word_count": 222,
  "mentions_ics": false,
  "published_at": "2026-07-13T12:00:00.000Z",
  "advisory_type": "alert",
  "outbound_links": [
    "https://edit.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cve.org/CVERecord?id=CVE-2008-4128",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities"
  ],
  "mentions_ransomware": false
}
showing 1–10 of 122older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cisa-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above