CIS Security Advisories
CIS Security News
CISA News
ISACA SmartBrief
Cyber Security Advisories – MS-ISAC
- Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution 2026-08-12Multiple vulnerabilities have been discovered in SonicWall Global Management System (GMS), the most severe of which could allow for remote code execution. The SonicWall Global Management System (GMS) is a centralized management interface used to deploy and centrally manage SonicWall firewall, wireless, email security, secure remote access and Dell X-Series solutions from a single console. […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-08-12Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- A Vulnerability in Zoom Clients Could Allow for Remote Code Execution 2026-08-12A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and […]
- Critical Patches Issued for Microsoft Products, August 11, 2026 2026-08-11Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-08-11Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe ColdFusion is a commercial rapid web application development platform and application server.Adobe Commerce is an enterprise-level e-commerce platform built on the proven technology of Magento.Adobe Lightroom is a popular cloud-based image organization and photo-editing software developed […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-08-07Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass 2026-08-03Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain […]
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution 2026-07-30Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install […]
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution 2026-07-28Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem.Adobe Format Plugins are software add-ons used by Adobe applications to […]
- A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution 2026-07-28A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. VeloCloud Orchestrator is a centralized management platform used to configure, provision, monitor, and troubleshoot software-defined wide area networks (SD-WAN) and SASE components across enterprise edges and gateways. Successful exploitation of this vulnerability may allow a remote attacker to […]
Blog Feed – Center for Internet Security
- UK Cyber Resilience: Closing the Execution Gap 2026-08-12A UK survey reveals cyber risk is growing, but cyber resilience is not keeping pace. Learn how CIS SecureSuite can help UK organizations move from awareness to execution.
- CIS Benchmarks August 2026 Update 2026-08-11The following CIS Benchmarks have been updated during the past month. We've highlighted the major updates below.
- Security Stagflation 2026-08-06What's security stagflation look like? The cost of finding bugs is down, but the cost of fixing them is the same. Here's what CISOs need to know.
- Strengthening Cyber Resilience Through Education via Essential Cyber Hygiene Bootcamp 2026-08-06Essential Cyber Hygiene Fundamentals Bootcamp helps cyber practitioners implement CIS IG1 Safeguards, reduce risk and strengthen organizational resilience.
- CIS Benchmarks July 2026 Update 2026-07-15These CIS Benchmarks and CIS Build Kits have been updated or recently released and include a full changelog that references all changes.
- Turning Secure Software Development into a Measurable Practice 2026-07-13CIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.
- 5 Major Emerging Risks to Large-Scale Events 2026-07-09To create safer, more secure large-scale events, read our recommendations for defending against five emerging risks to public gatherings.
- Cybersecurity Grant Funding: FEMA Clarifies SLCGP Use for CIS Services 2026-07-06FEMA clarifies that SLCGP/TCGP grants can fund CIS Services. See what qualifies, what's required, and what's next.
- 6 Key Takeaways: Strengthening Public Safety Through Collective Defense 2026-06-30Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.
- CIS Controls Accreditation Drives Global Cybersecurity Standards 2026-06-25CIS Controls Accreditation is raising global cybersecurity standards, setting a trusted benchmark for excellence, resilience, and best practices.
All CISA Advisories
- Mira Hormone Monitor, Mira Android App 2026-08-11View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, […]CISA
- CISA Adds Three Known Exploited Vulnerabilities to Catalog 2026-08-11CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities […]CISA
- Pulsetto Vagus Nerve Stimulator 2026-08-11View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Nerve Stimulator Hidden […]CISA
- Johnson Controls C-CURE 9000 and Victor application server (Update A) 2026-08-11View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected: C-CURE 9000CISA
- #StopRansomware: Gunra Ransomware 2026-08-10Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data […]CISA
- CISA Adds One Known Exploited Vulnerability to Catalog 2026-08-07CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates […]CISA
- CPDLC over ATN-B1 Vulnerabilities 2026-08-07View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness. The […]CISA
- Medixant RadiAnt DICOM 2026-08-06View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOMCISA
- Johnson Controls Inc. TL280 2026-08-06View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280CISA
- ABB Ability Zenon 2026-08-06View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of […]CISA
ISACA SmartBrief on Cybersecurity
- Uber Freight investigates breach claimed by Helix group 2026-08-13Uber Freight is investigating a data breach claimed by the Helix hacking group, which says it accessed email correspondence, -More-
- I think there are a lot more opportunities for second chances in our lives than we think. 2026-08-13Jean Smart, actor
- Employee input is key to effective AI policies 2026-08-13Organizations that involve employees in creating AI policies see better results and trust, says Monica Washington Rothbaum of -More-
- Ransomware targets Microsoft SharePoint vulnerability 2026-08-13Ransomware groups are exploiting a Microsoft SharePoint remote code execution vulnerability that allows low-privilege attacke -More-
- Study: AI patches for vulnerabilities show high failure rate 2026-08-13A study by 1Password reveals that AI-generated patches are effective only 46% of the time, often introducing new vulnerabilit -More-
- NIST seeks input on AI-driven modernization of NVD 2026-08-13The US National Institute for Standards and Technology is seeking public input on modernizing the National Vulnerability Data -More-
- Compromised LiteLLM releases expose organizations 2026-08-13Malicious LiteLLM releases on PyPI in March have exposed more than 2,500 organizations by stealing credentials such as cloud -More-