CIS Security Advisories
CIS Security News
CISA News
ISACA SmartBrief
Cyber Security Advisories – MS-ISAC
- Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution 2026-09-10Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the system.Ivanti Endpoint Manager Mobile (Ivanti EPMM) is a mobile management software engine that enables mobile device, […]
- A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution 2026-09-09A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-09-08Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution.Adobe ColdFusion is a commercial rapid web application development platform used to build, […]
- Critical Patches Issued for Microsoft Products, September 8, 2026 2026-09-08Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
- Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution 2026-09-07Multiple vulnerabilities have been discovered in Dell Secure Connect Gateway, the most severe of which could allow for arbitrary code execution. Dell Secure Connect Gateway is an enterprise monitoring and connection software for Dell infrastructure. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-09-05Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code Execution 2026-09-02Multiple Vulnerabilities have been discovered in SonicWall SMA1000 Series Appliances, which when chained together could allow for remote code execution, potentially leading to full system compromise. SonicWall Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade secure access and SSL VPN gateways. Successful exploitation of the vulnerabilities could allow for remote code execution.
- Multiple Vulnerabilities in PaperCut Products Could Allow for Remote Code Execution 2026-09-02Multiple vulnerabilities have been discovered in PaperCut products, the most severe of which could allow for remote code execution. PaperCut products are software tools used to track, control, secure, and manage printing, copying, and scanning across office and school printer networks. Successful exploitation of the most severe of these vulnerabilities could allow for remote code […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-09-02Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution 2026-08-19Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
Blog Feed – Center for Internet Security
- CIS Benchmarks September 2026 Update 2026-09-11The following CIS Benchmarks were updated during the past month. Each Benchmark includes a full changelog detailing all modifications and enhancements.
- Dual-RMM Phishing and PowerShell RAT Campaign Hits SLTTs 2026-09-01An active phishing campaign is targeting U.S. SLTTs with a custom PowerShell WebSocket RAT and dual RMM tools. Read the CIS CTI team's analysis.
- CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity 2026-08-26CIS and SANS extend decades of partnership with a new AWS Marketplace offering that combines secure cloud infrastructure and expert training.
- SLTT Traffic Directing to S3 Buckets Hosting KrustyLoader 2026-08-24The CIS CTI team identified several MS-ISAC members directing DNS traffic to AWS S3 buckets hosting Krustyloader malware. Read its analysis.
- 3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026 2026-08-19Lessons learned for securing large scale events and CIS's critical role as a partner supporting event security operations at the 2026 FIFA World Cup
- Vishing: An Evolving Threat to SLTT Organizations 2026-08-17The CIS CTI team assesses vishing will continue to pose a risk to U.S. SLTT organizations. Read the team's analysis and recommendations.
- Recent Water Utility Attacks Offer a Blueprint for Resilience 2026-08-14Recent attacks on water systems offer a blueprint for resilience. Explore five lessons utilities can use to strengthen cybersecurity and operations.
- UK Cyber Resilience: Closing the Execution Gap 2026-08-12A UK survey reveals cyber risk is growing, but cyber resilience is not keeping pace. Learn how CIS SecureSuite can help UK organizations move from awareness to execution.
- CIS Benchmarks August 2026 Update 2026-08-11The following CIS Benchmarks have been updated during the past month. We've highlighted the major updates below.
- Security Stagflation 2026-08-06What's security stagflation look like? The cost of finding bugs is down, but the cost of fixing them is the same. Here's what CISOs need to know.
All CISA Advisories
- CISA Adds One Known Exploited Vulnerability to Catalog 2026-09-11CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: […]CISA
- CISA Adds Three Known Exploited Vulnerabilities to Catalog 2026-09-11CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and […]CISA
- NextGen Healthcare Mirth Connect 2026-09-10View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth ConnectCISA
- ST Engineering iDirect iQ-Series Terminals (Update A) 2026-09-10View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminalsCISA
- AVEVA Pipeline Integrity Monitor 2026-09-10View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity MonitorCISA
- Orthanc DICOM Server 2026-09-10View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM […]CISA
- CISA Adds Two Known Exploited Vulnerabilities to Catalog 2026-09-10CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose […]CISA
- CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-09-09CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication […]CISA
- CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-09-08CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code […]CISA
- CareCam Pro IP Cameras 2026-09-08View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities […]CISA
ISACA SmartBrief on Cybersecurity
- True heroism is remarkably sober, very undramatic. It is not the urge to surpass all others at whatever cost, but the urge to serve others at whatever cost. 2026-09-14Arthur Ashe, professional tennis player
- Register for ISACA 2026 Europe 2026-09-14Immerse yourself in premier IS/IT content, network with like-minded professionals, and hear from insightful thought leaders a -More-
- Enter now: SmartBrief Innovation Awards in AI 2026 2026-09-14SmartBrief has opened entries for the 2026 Innovation Awards in AI, which recognize AI solutions that impact business operati -More-
- Hibbett reports employee data breach 2026-09-14Hibbett Retail has notified employees of a data breach in which an unauthorized third party accessed systems and potentially -More-
- AI's Impact on Security: Hardening the Agentic Surface 2026-09-14With the focus shifting from high-level theory to tactical reality, security leaders are facing a massive expansion of the co -More-
- Be proactive with a ransomware decision tree 2026-09-14Kerri Shafer-Page, vice president of incident response at Arctic Wolf, emphasizes the importance of preparing a ransomware de -More-
- CISOs face dual compliance challenge from UK, EU 2026-09-14The EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities within 24 hours, while the UK -More-
- Threat actors use BYOD to exploit Microsoft Graph API 2026-09-14Threat actors are exploiting personal devices to bypass corporate security, using Microsoft's Graph API to exfiltrate data fr -More-
- WatchGuard Firebox vulnerability used in ransomware 2026-09-14The Cybersecurity and Infrastructure Security Agency has confirmed that a vulnerability in WatchGuard Firebox has been used i -More-
- Surfshark incident exposes internal server misconfiguration 2026-09-14Surfshark has disclosed a cybersecurity incident involving a misconfigured test server that was accessed by hackers. -More-