CIS Security Advisories
CIS Security News
CISA News
ISACA SmartBrief
Cyber Security Advisories – MS-ISAC
- A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution 2026-07-20A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-07-15Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-07-14Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe After Effects is a digital visual effects and motion graphics application used for creating cinematic movie titles, transitions, and complex animation sequences.Adobe Animate is a professional vector animation software used to design interactive animations and multimedia […]
- Critical Patches Issued for Microsoft Products, July 14, 2026 2026-07-14Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-07-01Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Campaign Classic is an enterprise-grade marketing automation platform that helps organizations design, automate, and track complex, personalized cross-channel marketing campaigns.Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web […]
- Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution 2026-07-01Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet.Thunderbird is a free, open-source email, calendar, and chat application.Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-07-01Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-06-26Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- A Vulnerability in PAN-OS Could Allow for Authentication Bypass 2026-06-22A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. The PAN-OS GlobalProtect Portal acts as the central control plane for Palo Alto Networks VPN infrastructure. Successful exploitation of the vulnerability allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
- Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution 2026-06-16Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet.Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations.Thunderbird is a free, open-source email, calendar, and chat application.Successful exploitation […]
Blog Feed – Center for Internet Security
- CIS Benchmarks July 2026 Update 2026-07-15These CIS Benchmarks and CIS Build Kits have been updated or recently released and include a full changelog that references all changes.
- Turning Secure Software Development into a Measurable Practice 2026-07-13CIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.
- 5 Major Emerging Risks to Large-Scale Events 2026-07-09To create safer, more secure large-scale events, read our recommendations for defending against five emerging risks to public gatherings.
- Cybersecurity Grant Funding: FEMA Clarifies SLCGP Use for CIS Services 2026-07-06FEMA clarifies that SLCGP/TCGP grants can fund CIS Services. See what qualifies, what's required, and what's next.
- 6 Key Takeaways: Strengthening Public Safety Through Collective Defense 2026-06-30Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.
- CIS Controls Accreditation Drives Global Cybersecurity Standards 2026-06-25CIS Controls Accreditation is raising global cybersecurity standards, setting a trusted benchmark for excellence, resilience, and best practices.
- CIS Benchmarks June 2026 Update 2026-06-18The following CIS Benchmarks and CIS Build Kits have been updated or recently released. We've highlighted the major updates below.
- Keep up with HIPAA Expectations amid Growing Cyber Threats 2026-06-16Healthcare organizations can satisfy cybersecurity and HIPAA compliance obligations while upholding patient safety. Read on to learn how.
- CIS Controls Community Volunteer Spotlight: Diego Bolatti 2026-06-12Diego Bolatti advances CIS Controls adoption for SMEs through research, policy templates, and AI-driven cybersecurity tools.
- The Return of MCAP: Malware Analysis Built for SLTT Members 2026-06-11Our Malicious Code Analysis Platform (MCAP) supports malware analysis specifically designed for SLTT teams. Read our blog post to learn more.
All CISA Advisories
- CISA Adds Two Known Exploited Vulnerabilities to Catalog 2026-07-22CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal […]CISA
- Rockwell Automation Studio 5000 Logix Designer 2026-07-21View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 […]CISA
- Rockwell Automation 1718-AENTR/1719-AENTR 2026-07-21View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1718-AENTR/1719-AENTR Allocation of Resources Without Limits or Throttling Background Critical […]CISA
- Rockwell Automation 1734 POINT I/O 2026-07-21View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1734 POINT I/O Allocation of Resources Without Limits or […]CISA
- Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW 2026-07-21View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto […]CISA
- Siemens IAM Client 2026-07-21View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products […]CISA
- CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-07-21CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability CVE-2026-60137 WordPress Core SQL Injection Vulnerability These types of vulnerabilities are frequent […]CISA
- Siemens SIDIS Secured SmartPlug 2026-07-21View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured […]CISA
- Siemens CADRA 2026-07-21View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are […]CISA
- Rockwell Automation FactoryTalk Services Platform 2026-07-21View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are affected: FactoryTalk Directory (FTSP) 6.60 CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Services […]CISA
ISACA SmartBrief on Cybersecurity
- Nov. 16-19, Las Vegas: ISACA Training Week 2026-07-22Sharpen your skills to use for your next project, promotion and overall career development. -More-
- And the summer seems as though it would dream on for ever. 2026-07-22Elizabeth Von Arnim, writer
- Data breach at Partnered Health affects 21 clinics 2026-07-22Partnered Health is investigating a data breach that affected at least 21 clinics in Australia, resulting in the theft of per -More-
- Data layer resilience crucial amid "inevitable" breaches 2026-07-22With cyberattacks increasingly inevitable, organizations must prioritize quick recovery, which hinges on the data layer's res -More-
- Sorting through security complexity With ISACA's CISM credential 2026-07-22CISM credential holders share how the certification provides security managers with a strong foundation for navigating an inc -More-
- AI adoption increases stress, liability concerns for CISOs 2026-07-22The rapid adoption of AI technologies has increased stress among CISOs, with 26% considering leaving their jobs in the past y -More-
- Clients reluctant to email data amid cybersecurity fears 2026-07-22Clients are increasingly hesitant to email sensitive financial information to accountants because of cybersecurity concerns, -More-
- GAO: FAA, TSA must bolster aviation cybersecurity efforts 2026-07-22The Government Accountability Office has found significant issues with how the Federal Aviation Administration and the Transp -More-
- Forrester: AI agents pose top cybersecurity threat for 2026 2026-07-22AI agent threats are the top cybersecurity risk for 2026, Forrester reports. -More-