What PatchOwner would have told you
Replay of the CISA Known Exploited Vulnerabilities catalog (version 2026.09.11) over the last 90 days against inventory.csv (16 assets).
58 advisories were never shown to anyone because nothing in your inventory matched. That silence is the product.
Notices, most urgent first
Action needed: update Branch VPN appliance
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
- Where
- Branch VPN appliance · production · reachable from the internet
- Why it matters
- SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-15409)
- CISA confirms CVE-2026-15409 is exploited in the wild (added 2026-07-14).
- CISA reports use in ransomware campaigns.
- Federal remediation due date: 2026-07-17.
- Product match is exact: vendor and product names match (100%).
- Version 12.4.3 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-15409 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Branch VPN appliance
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
- Where
- Branch VPN appliance · production · reachable from the internet
- Why it matters
- SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-15410)
- CISA confirms CVE-2026-15410 is exploited in the wild (added 2026-07-14).
- CISA reports use in ransomware campaigns.
- Federal remediation due date: 2026-07-17.
- Product match is exact: vendor and product names match (100%).
- Version 12.4.3 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-15410 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update HQ VPN gateway
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Fortinet FortiOS (you run FortiOS 7.2.8)
- Where
- HQ VPN gateway · production · reachable from the internet
- Why it matters
- Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2025-68686)
- CISA confirms CVE-2025-68686 is exploited in the wild (added 2026-07-27).
- Federal remediation due date: 2026-08-10.
- Product match is exact: vendor and product names match (100%).
- Version 7.2.8 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2025-68686 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update RMM platform
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- N-able N-central (you run N-central 2024.1)
- Where
- RMM platform · production · reachable from the internet
- Why it matters
- N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-18577)
- CISA confirms CVE-2026-18577 is exploited in the wild (added 2026-08-03).
- Federal remediation due date: 2026-08-06.
- Product match is exact: vendor and product names match (100%).
- Version 2024.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-18577 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update RMM platform
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- N-able N-central (you run N-central 2024.1)
- Where
- RMM platform · production · reachable from the internet
- Why it matters
- N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-18556)
- CISA confirms CVE-2026-18556 is exploited in the wild (added 2026-08-04).
- Federal remediation due date: 2026-08-07.
- Product match is exact: vendor and product names match (100%).
- Version 2024.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-18556 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Mail server
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Synacor Zimbra Collaboration Suite (ZCS) (you run Zimbra Collaboration Suite 10.0)
- Where
- Mail server · production · reachable from the internet
- Why it matters
- Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating sy…
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-73570)
- CISA confirms CVE-2026-73570 is exploited in the wild (added 2026-08-21).
- Federal remediation due date: 2026-08-24.
- Product match is exact: vendor and product names match (100%).
- Version 10.0 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-73570 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Remote desktop gateway
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Citrix NetScaler ADC and NetScaler Gateway (you run NetScaler Gateway 14.1)
- Where
- Remote desktop gateway · production · reachable from the internet
- Why it matters
- Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-8452)
- CISA confirms CVE-2026-8452 is exploited in the wild (added 2026-08-26).
- Federal remediation due date: 2026-08-29.
- Product match is exact: vendor and product names match (100%).
- Version 14.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-8452 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Branch VPN appliance
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
- Where
- Branch VPN appliance · production · reachable from the internet
- Why it matters
- SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operati…
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-83548)
- CISA confirms CVE-2026-83548 is exploited in the wild (added 2026-09-02).
- Federal remediation due date: 2026-09-05.
- Product match is exact: vendor and product names match (100%).
- Version 12.4.3 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-83548 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Branch VPN appliance
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
- Where
- Branch VPN appliance · production · reachable from the internet
- Why it matters
- SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-83549)
- CISA confirms CVE-2026-83549 is exploited in the wild (added 2026-09-02).
- Federal remediation due date: 2026-09-05.
- Product match is exact: vendor and product names match (100%).
- Version 12.4.3 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-83549 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Web store
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Adobe Commerce and Magento (you run Magento 2.4.6)
- Where
- Web store · production · reachable from the internet
- Why it matters
- Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-75650)
- CISA confirms CVE-2026-75650 is exploited in the wild (added 2026-09-08).
- Federal remediation due date: 2026-09-11.
- Product match is exact: vendor and product names match (100%).
- Version 2.4.6 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-75650 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update RMM platform
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- N-able N-central (you run N-central 2024.1)
- Where
- RMM platform · production · reachable from the internet
- Why it matters
- N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-86218)
- CISA confirms CVE-2026-86218 is exploited in the wild (added 2026-09-08).
- Federal remediation due date: 2026-09-11.
- Product match is exact: vendor and product names match (100%).
- Version 2024.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-86218 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Remote desktop gateway
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Citrix NetScaler (you run NetScaler Gateway 14.1)
- Where
- Remote desktop gateway · production · reachable from the internet
- Why it matters
- Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-19490)
- CISA confirms CVE-2026-19490 is exploited in the wild (added 2026-09-09).
- Federal remediation due date: 2026-09-12.
- Product match is exact: vendor and product names match (100%).
- Version 14.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-19490 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update HQ VPN gateway
Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Fortinet Multiple Products (you run FortiOS 7.2.8)
- Where
- HQ VPN gateway · production · reachable from the internet
- Why it matters
- Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
- When
- Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2025-25249)
- CISA confirms CVE-2025-25249 is exploited in the wild (added 2026-09-09).
- Federal remediation due date: 2026-09-12.
- Product match is likely: Fortinet advisory names FortiOS in its description.
- Version 7.2.8 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2025-25249 as exploited in the wild.
- System Exposure = open: the inventory marks this asset internet-facing.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Wi-Fi controller
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Ubiquiti UniFi OS (you run UniFi OS 4.1)
- Where
- Wi-Fi controller · production
- Why it matters
- Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-34910)
- CISA confirms CVE-2026-34910 is exploited in the wild (added 2026-06-23).
- Federal remediation due date: 2026-06-26.
- Product match is exact: vendor and product names match (100%).
- Version 4.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-34910 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Wi-Fi controller
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Ubiquiti UniFi OS (you run UniFi OS 4.1)
- Where
- Wi-Fi controller · production
- Why it matters
- Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-34909)
- CISA confirms CVE-2026-34909 is exploited in the wild (added 2026-06-23).
- Federal remediation due date: 2026-06-26.
- Product match is exact: vendor and product names match (100%).
- Version 4.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-34909 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Wi-Fi controller
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Ubiquiti UniFi OS (you run UniFi OS 4.1)
- Where
- Wi-Fi controller · production
- Why it matters
- Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-34908)
- CISA confirms CVE-2026-34908 is exploited in the wild (added 2026-06-23).
- Federal remediation due date: 2026-06-26.
- Product match is exact: vendor and product names match (100%).
- Version 4.1 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-34908 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Intranet portal
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft SharePoint Server (you run SharePoint Server 2019)
- Where
- Intranet portal · production
- Why it matters
- Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-45659)
- CISA confirms CVE-2026-45659 is exploited in the wild (added 2026-07-01).
- CISA reports use in ransomware campaigns.
- Federal remediation due date: 2026-07-04.
- Product match is exact: vendor and product names match (100%).
- Version 2019 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-45659 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Intranet portal
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft SharePoint Server (you run SharePoint Server 2019)
- Where
- Intranet portal · production
- Why it matters
- Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-56164)
- CISA confirms CVE-2026-56164 is exploited in the wild (added 2026-07-14).
- Federal remediation due date: 2026-07-17.
- Product match is exact: vendor and product names match (100%).
- Version 2019 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-56164 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Intranet portal
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft SharePoint (you run SharePoint Server 2019)
- Where
- Intranet portal · production
- Why it matters
- Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-58644)
- CISA confirms CVE-2026-58644 is exploited in the wild (added 2026-07-16).
- Federal remediation due date: 2026-07-19.
- Product match is exact: vendor and product names match (100%).
- Version 2019 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-58644 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Intranet portal
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft SharePoint (you run SharePoint Server 2019)
- Where
- Intranet portal · production
- Why it matters
- Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-50522)
- CISA confirms CVE-2026-50522 is exploited in the wild (added 2026-07-22).
- Federal remediation due date: 2026-07-25.
- Product match is exact: vendor and product names match (100%).
- Version 2019 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-50522 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Build server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy
⚠️
- What is affected
- JetBrains TeamCity (you run TeamCity 2024.03)
- Where
- Build server · staging
- Why it matters
- JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-63077)
- CISA confirms CVE-2026-63077 is exploited in the wild (added 2026-08-05).
- Federal remediation due date: 2026-08-08.
- Product match is exact: vendor and product names match (100%).
- Version 2024.03 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-63077 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = low: this is a staging system; mission impact is at most degraded.
- Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update File server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft Windows Ancillary Function Driver for WinSock (you run Windows Server 2022)
- Where
- File server · production
- Why it matters
- Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-68820)
- CISA confirms CVE-2026-68820 is exploited in the wild (added 2026-08-11).
- Federal remediation due date: 2026-08-25.
- Product match is exact: vendor and product names match (100%).
- Version 2022 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-68820 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Virtualization manager
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a lot.Show me in the policy
⚠️
- What is affected
- Broadcom VMware vCenter (you run vCenter Server 8.0u2)
- Where
- Virtualization manager · production
- Why it matters
- Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-59310)
- CISA confirms CVE-2026-59310 is exploited in the wild (added 2026-08-18).
- CISA reports use in ransomware campaigns.
- Federal remediation due date: 2026-08-21.
- Product match is exact: vendor and product names match (100%).
- Version 8.0u2 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-59310 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = high: criticality 'high' in the inventory.
- Decided by SEI deployer tree (default), row 62 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:H/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Intranet portal
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft SharePoint (you run SharePoint Server 2019)
- Where
- Intranet portal · production
- Why it matters
- Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-55040)
- CISA confirms CVE-2026-55040 is exploited in the wild (added 2026-08-18).
- Federal remediation due date: 2026-08-21.
- Product match is exact: vendor and product names match (100%).
- Version 2019 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-55040 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Print server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy
⚠️
- What is affected
- PaperCut NG/MF (you run PaperCut MF 22.1)
- Where
- Print server · production
- Why it matters
- PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the securit…
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-82078)
- CISA confirms CVE-2026-82078 is exploited in the wild (added 2026-08-31).
- Federal remediation due date: 2026-09-14.
- Product match is exact: vendor and product names match (100%).
- Version 22.1 was not checked; the CISA feed does not list affected versions.
- No owner recorded for this asset; routed to the fallback contact.
- Exploitation = active: CISA lists CVE-2026-82078 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = low: criticality 'low' in the inventory.
- Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update Print server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy
⚠️
- What is affected
- PaperCut NG/MF (you run PaperCut MF 22.1)
- Where
- Print server · production
- Why it matters
- PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-81578)
- CISA confirms CVE-2026-81578 is exploited in the wild (added 2026-08-31).
- Federal remediation due date: 2026-09-14.
- Product match is exact: vendor and product names match (100%).
- Version 22.1 was not checked; the CISA feed does not list affected versions.
- No owner recorded for this asset; routed to the fallback contact.
- Exploitation = active: CISA lists CVE-2026-81578 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = low: criticality 'low' in the inventory.
- Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update File server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft Windows (you run Windows Server 2022)
- Where
- File server · production
- Why it matters
- Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-81963)
- CISA confirms CVE-2026-81963 is exploited in the wild (added 2026-09-08).
- Federal remediation due date: 2026-09-22.
- Product match is exact: vendor and product names match (100%).
- Version 2022 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-81963 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Action needed: update File server
Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy
⚠️
- What is affected
- Microsoft Windows (you run Windows Server 2022)
- Where
- File server · production
- Why it matters
- Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
- When
- Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
- What to do
- Apply mitigations in accordance with vendor instructions.
Nobody has acted on this yet.
For the auditor (CVE-2026-85880)
- CISA confirms CVE-2026-85880 is exploited in the wild (added 2026-09-08).
- Federal remediation due date: 2026-09-22.
- Product match is exact: vendor and product names match (100%).
- Version 2022 was not checked; the CISA feed does not list affected versions.
- Exploitation = active: CISA lists CVE-2026-85880 as exploited in the wild.
- System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
- Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
- Human Impact = medium: criticality 'medium' in the inventory.
- Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector
SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days. - CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Does this apply? HQ VPN gateway
Watch, because we are not sure this product is the one on this asset.
⚠️
- What is affected
- Fortinet FortiSandbox (you run FortiOS 7.2.8)
- Where
- HQ VPN gateway · production · reachable from the internet
- Why it matters
- Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP reques…
- When
- No action yet. Tell us whether this product is really in use. Acknowledge within 7 days.
- What to do
- Tell us whether this product is really in use. If it is, follow the vendor fix.
Nobody has acted on this yet.
For the auditor (CVE-2026-25089)
- CISA confirms CVE-2026-25089 is exploited in the wild (added 2026-07-16).
- Federal remediation due date: 2026-07-19.
- Product match is possible: vendor matches; product name only partly matches (63%).
- Version 7.2.8 was not checked; the CISA feed does not list affected versions.
- CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Does this apply? HQ VPN gateway
Watch, because we are not sure this product is the one on this asset.
⚠️
- What is affected
- Fortinet FortiSandbox (you run FortiOS 7.2.8)
- Where
- HQ VPN gateway · production · reachable from the internet
- Why it matters
- Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
- When
- No action yet. Tell us whether this product is really in use. Acknowledge within 7 days.
- What to do
- Tell us whether this product is really in use. If it is, follow the vendor fix.
Nobody has acted on this yet.
For the auditor (CVE-2026-39808)
- CISA confirms CVE-2026-39808 is exploited in the wild (added 2026-07-16).
- Federal remediation due date: 2026-07-19.
- Product match is possible: vendor matches; product name only partly matches (63%).
- Version 7.2.8 was not checked; the CISA feed does not list affected versions.
- CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Who would have heard from us, and how much
| Person | Full notices, to fix | One-line statuses | Hears only if stuck |
|---|---|---|---|
| Dana Ruiz dana@acme.example | 13 | ||
| SOC soc@acme.example | 13 | ||
| Priya Shah priya@acme.example | 13 | ||
| CIO cio@acme.example | 17 | ||
| CISO ciso@acme.example | 11 | ||
| LENA lena@acme.example | 8 | ||
| Sam Lee sam@acme.example | 2 | ||
| Security team security@example.com | 2 | ||
| Marco marco@acme.example | 4 |
What the accountable people see
The whole message. No CVE numbers, no descriptions, no links to advisories.
3 urgent technology risks need attention
- Act nowBranch VPN appliance: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Act nowHQ VPN gateway: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Act nowRemote desktop gateway: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Update soonWi-Fi controller: update soon. Assigned to Dana Ruiz. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
3 urgent technology risks need attention
- Act nowRMM platform: act now. Assigned to Priya Shah. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Act nowMail server: act now. Assigned to Priya Shah. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Act nowWeb store: act now. Assigned to Sam Lee. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
- Update soonIntranet portal: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
- Update soonBuild server: update soon. Assigned to Sam Lee. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
- Update soonFile server: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
- Update soonVirtualization manager: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
- Update soonPrint server: update soon. Assigned to Security team. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
Why was this not sent?
Your policy, in plain words. Every exploited vulnerability that touches something you own is handled like this:
- Reachable from the internet and the attack can run by itself: Update soon; Act now if it would hurt a lot or more.
- Reachable from the internet but the attack needs a person: Update soon; Plan update if it would only hurt a little; Act now if it could stop the business.
- Reachable from inside only and the attack can run by itself: Update soon.
- Reachable from inside only but the attack needs a person: Plan update; Update soon if it would hurt a lot or more.
- Isolated and the attack can run by itself: Update soon; Plan update if it would only hurt a little.
- Isolated but the attack needs a person: Plan update; Update soon if it would hurt a lot or more.
⚠️ Defer and Plan update are simulated answers for testing the prioritization logic. Every vulnerability in this replay is actively exploited, and CISA's guidance is to patch immediately. A policy that defers one is yours to defend, not CISA's and not this tool's.
To change the policy, change an answer below. Three questions, in order, then an answer. Everything on this page recomputes. The wording is the SEI/CERT SSVC deployer tree underneath, so an auditor can trace every decision.
Can attackers reach it? from the internet14
Can the attack run by itself? no, it needs a person0
Can the attack run by itself? yes14
Can attackers reach it? from inside only16
Can the attack run by itself? no, it needs a person0
Can the attack run by itself? yes16
Can attackers reach it? isolated0
Can the attack run by itself? no, it needs a person0
Can the attack run by itself? yes0
What each answer means for people
The tree ends in an answer. This table is what the answer does. It is the other half of the policy, and it is four rows.
| Answer | Who gets the full notice | Acknowledge within | Plan within | Escalate after | Digest allowed |
|---|---|---|---|---|---|
| Act now | owner and on-call | 2 hours | 8 hours | 24 hours | no |
| Update soon | owner | 2 days | 7 days | 7 days | no |
| Plan update ⚠️ simulated | owner | 7 days | 30 days | 30 days | yes |
| Defer ⚠️ simulated | nobody; listed under “why was this not sent” | – | – | – | yes |
Every answer also sends one status line to the accountable person on the asset, if there is one. Escalation contacts hear nothing unless the window passes.
Your edited policy file
Copy this into a file and run patchowner replay --policy yourfile.csv. Unchanged until you edit an answer.
3 things to fix, worst first. Each one says what to do.
Can PatchOwner route a notice for every asset, is the catalog current, and is anyone acting on what was sent? Each line is what good looks like, how many rows meet it, and the one thing to do.
Health never changes a decision. It tells the person running the replay where the inventory or the follow-through is thin.
What this is
PatchOwner is a proof of concept. It replays the CISA Known Exploited Vulnerabilities catalog against a list of technology you run and shows which notices would have gone to whom, which stayed quiet, and why. It exists to test one idea: that fewer, owned, plainly worded notices get acted on, and floods do not.
Read this before you rely on anything here
⚠️ This site is for educational and testing purposes only. Recommendations shown here are not professional security advice. For vulnerabilities on the CISA KEV catalog, the default action is immediate patching per CISA guidance. Always verify against vendor advisories and consult your security team before deferring any update.
Every vulnerability in this report is on the KEV catalog, which means it is being exploited in the wild right now. The urgency shown on each notice comes from a policy table that you can edit on the Policy tab. When that table says Defer or Plan update, the notice says so with a caution, because that answer is the organization's risk appetite and not CISA's guidance, not the vendor's, and not this tool's. The default table is the SEI/CERT SSVC example, used unchanged so that teams can compare; it is a worked example from a research paper, not a recommendation.
What is fact and what is estimate
Facts come from CISA (that a vulnerability is exploited, the vendor and product named, the required action) and from your inventory (what you run, who owns it, whether it is reachable from the internet). Estimates are PatchOwner's own: whether an advisory matches an inventory row, and whether an attack can run without a person. Every estimate is labeled under "For the auditor" on each notice, and an estimate never lowers urgency on its own. Versions are never assumed: KEV carries no version data, so no notice claims a version is affected.
What people did
The buttons on each notice record what a person did. In the hosted demo that goes to a small file on the server; in a downloaded report it stays in your browser. Nothing here sends email, opens tickets, or contacts anyone.
Credits
Idea, doctrine, and product direction: Robert Sweetman. Code and instructions to run it on your own inventory: github.com/e-allora/patchowner. Implementation: written with Claude (Anthropic), Claude Fable 5.1, in Claude Code, September 2026. Decision vocabulary: SSVC version 2.0, Software Engineering Institute, Carnegie Mellon University (Spring et al., April 2021). Exploited-vulnerability data: CISA Known Exploited Vulnerabilities catalog. Licensed under the Business Source License 1.1.
Facts come from CISA and the inventory. Estimates are PatchOwner's own matching and mapping and are labeled as such. An estimate never lowers urgency on its own. Versions are never assumed. Decision vocabulary: SSVC v2, SEI/CERT, Carnegie Mellon University.