CIS Security Advisories
CIS Security News
CISA News
ISACA SmartBrief
Cyber Security Advisories – MS-ISAC
- A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code Execution 2026-09-23A vulnerability has been discovered in F5 BIG-IP Access Policy Manager (APM) that could allow for remote code execution. BIG-IP APM is a widely deployed network access and identity management solution used across government agencies, financial institutions, healthcare organizations, and large enterprises to control application and network access. Successful exploitation of this vulnerability could result […]
- Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution 2026-09-17Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
- Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution 2026-09-15Multiple vulnerabilities have been discovered in Cisco Secure Email products, the most severe of which could allow for remote code execution.Cisco Secure Email Gateway (formerly ESA) is an email security appliance that filters spam, malware, and other threats at the mail gateway.Cisco Secure Email and Web Manager (formerly SMA) is a centralized management and reporting […]
- Multiple Vulnerabilities in Mikrotik Routers Could Allow for Admin Hijacking 2026-09-14Multiple vulnerabilities have been discovered in MikroTik Routers, the most severe of which could allow for admin hijacking. MikroTik routers are network devices that use the RouterOS operating system to provide advanced routing, firewall, wireless, VPN, bandwidth management, and network security features for homes, businesses, and internet service providers. Successful exploitation of the most severe […]
- A Vulnerability in GitLab Could Allow for Disclosure of Sensitive Data 2026-09-14A vulnerability has been discovered in GitLab, which could allow disclosure of sensitive data. GitLab GitLab is a DevOps platform that provides source code management, CI/CD pipelines, issue tracking, and collaboration tools in a single application for software development teams. Successful exploitation of this vulnerability could allow for path traversal, leading to disclosure of potentially […]
- Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution 2026-09-10Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the system.Ivanti Endpoint Manager Mobile (Ivanti EPMM) is a mobile management software engine that enables mobile device, […]
- A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution 2026-09-09A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-09-08Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution.Adobe ColdFusion is a commercial rapid web application development platform used to build, […]
- Critical Patches Issued for Microsoft Products, September 8, 2026 2026-09-08Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
- Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution 2026-09-07Multiple vulnerabilities have been discovered in Dell Secure Connect Gateway, the most severe of which could allow for arbitrary code execution. Dell Secure Connect Gateway is an enterprise monitoring and connection software for Dell infrastructure. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the […]
Blog Feed – Center for Internet Security
- CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action 2026-09-21Learn how CDM v3.0 helps organizations identify high-value CIS Controls Safeguards, strengthen cyber resilience, and reduce risk with confidence.
- CIS Benchmarks September 2026 Update 2026-09-11The following CIS Benchmarks were updated during the past month. Each Benchmark includes a full changelog detailing all modifications and enhancements.
- Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs 2026-09-01An active phishing campaign is targeting U.S. SLTTs with a custom PowerShell WebSocket RAT and dual RMM tools. Read the CIS CTI team's analysis.
- CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity 2026-08-26CIS and SANS extend decades of partnership with a new AWS Marketplace offering that combines secure cloud infrastructure and expert training.
- SLTT Traffic Directing to S3 Buckets Hosting KrustyLoader 2026-08-24The CIS CTI team identified several MS-ISAC members directing DNS traffic to AWS S3 buckets hosting Krustyloader malware. Read its analysis.
- 3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026 2026-08-19Lessons learned for securing large scale events and CIS's critical role as a partner supporting event security operations at the 2026 FIFA World Cup
- Vishing: An Evolving Threat to SLTT Organizations 2026-08-17The CIS CTI team assesses vishing will continue to pose a risk to U.S. SLTT organizations. Read the team's analysis and recommendations.
- Recent Water Utility Attacks Offer a Blueprint for Resilience 2026-08-14Recent attacks on water systems offer a blueprint for resilience. Explore five lessons utilities can use to strengthen cybersecurity and operations.
- UK Cyber Resilience: Closing the Execution Gap 2026-08-12A UK survey reveals cyber risk is growing, but cyber resilience is not keeping pace. Learn how CIS SecureSuite can help UK organizations move from awareness to execution.
- CIS Benchmarks August 2026 Update 2026-08-11The following CIS Benchmarks have been updated during the past month. We've highlighted the major updates below.
All CISA Advisories
- lwIP TCP/IP Stack MQTT Client Application 2026-09-22View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT Client Application >=2.0.1|=2.0.1|CISA
- Siemens SIMOVE Fleetmanager and SIPLANT 2026-09-22View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens SIMOVE Fleetmanager and SIPLANT are affected: SIMOVE Fleetmanager V3.1 […]CISA
- Siemens Siveillance Control 2026-09-22View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and […]CISA
- Siemens SIPLUS and SIMATIC Products 2026-09-22View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens […]CISA
- Siemens Desigo CC family 2026-09-22View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client […]CISA
- Siemens WTV676 and WTV776 2026-09-22View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions. […]CISA
- lwIP (Lightweight IP) 2026-09-22View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|=2.0.1|CISA
- CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-09-22CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability These types of […]CISA
- OpenPLC Runtime v3 2026-09-22View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment […]CISA
- Siemens Industrial Edge Management 2026-09-22View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Industrial Edge […]CISA
ISACA SmartBrief on Cybersecurity
- I wake up every morning with a decent amount of anxiety thinking that I didn't do nearly enough good work yesterday and how ... am I going to be inspired enough today to do the work I'm supposed get done by tomorrow. 2026-09-22Duncan Sheik, singer, songwriter, composer 1969-2026
- AI's Impact on Security: Hardening the Agentic Surface 2026-09-22With the focus shifting from high-level theory to tactical reality, security leaders are facing a massive expansion of the co -More-
- Enter now: SmartBrief Innovation Awards in AI 2026 2026-09-22SmartBrief has opened entries for the 2026 Innovation Awards in AI, which recognize AI solutions that impact business operati -More-
- AI shifts cybersecurity roles, skills demand 2026-09-22AI is transforming the cybersecurity job market by consolidating roles, elevating the importance of judgment over technical s -More-
- Register by Oct. 2: ISACA 2026 Europe 2026-09-22Immerse yourself in premier IS/IT content, network with like-minded professionals, and hear from insightful thought leaders a -More-
- Researchers find, OpenAI fixes Codex sandbox escapes 2026-09-22Security researchers discovered two vulnerabilities in OpenAI Codex that allowed sandbox escapes, with one flaw, "Heapjack," -More-
- Jade Sleet targets IT services with macOS backdoors 2026-09-22Threat actor Jade Sleet has targeted an IT services company using macOS backdoors FLATROOF and ROOFDECK, SentinelOne reports. -More-
- Task#Stomp backdoor targets business documents 2026-09-22Researchers have analyzed Task#Stomp, a Windows backdoor that targets business documents by searching drives and uploading fi -More-
- Google: Gemini AI accidentally breaches company systems 2026-09-22Google has confirmed that its Gemini AI model inadvertently accessed the systems of a trio of real companies during a test in -More-
- Insight: How workforce challenges are tied to State of Cyber 2026-09-22Members of ISACA's Emerging Trends Working Group offer their views on the findings of the recent State of Cybersecurity repor -More-