What PatchOwner would have told you

Replay of the CISA Known Exploited Vulnerabilities catalog (version 2026.09.11) over the last 90 days against inventory.csv (16 assets).

90advisories published
32touched something you own
30notices sent
2suppressed, with a reason
2had no owner on file
30open, nobody has acted
0acknowledged
0assigned
0fixed

58 advisories were never shown to anyone because nothing in your inventory matched. That silence is the product.

dana@acme.example would have received 11 urgent notices in 90 days. Consider routing lower-confidence items to a weekly digest.
priya@acme.example would have received 13 urgent notices in 90 days. Consider routing lower-confidence items to a weekly digest.

Notices, most urgent first

Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Branch VPN appliance

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
Where
Branch VPN appliance · production · reachable from the internet
Why it matters
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-15409)
  • CISA confirms CVE-2026-15409 is exploited in the wild (added 2026-07-14).
  • CISA reports use in ransomware campaigns.
  • Federal remediation due date: 2026-07-17.
  • Product match is exact: vendor and product names match (100%).
  • Version 12.4.3 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-15409 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Branch VPN appliance

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

Question for a person: CISA's text mentions “authenticated attacker”. Does this attack need a person's help?
What is affected
SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
Where
Branch VPN appliance · production · reachable from the internet
Why it matters
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-15410)
  • CISA confirms CVE-2026-15410 is exploited in the wild (added 2026-07-14).
  • CISA reports use in ransomware campaigns.
  • Federal remediation due date: 2026-07-17.
  • Product match is exact: vendor and product names match (100%).
  • Version 12.4.3 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-15410 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update HQ VPN gateway

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Fortinet FortiOS (you run FortiOS 7.2.8)
Where
HQ VPN gateway · production · reachable from the internet
Why it matters
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2025-68686)
  • CISA confirms CVE-2025-68686 is exploited in the wild (added 2026-07-27).
  • Federal remediation due date: 2026-08-10.
  • Product match is exact: vendor and product names match (100%).
  • Version 7.2.8 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2025-68686 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Priya Shah and SOC · status to LENA · CIO hears only if unresolved after 24 hours

Action needed: update RMM platform

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
N-able N-central (you run N-central 2024.1)
Where
RMM platform · production · reachable from the internet
Why it matters
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-18577)
  • CISA confirms CVE-2026-18577 is exploited in the wild (added 2026-08-03).
  • Federal remediation due date: 2026-08-06.
  • Product match is exact: vendor and product names match (100%).
  • Version 2024.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-18577 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Priya Shah and SOC · status to LENA · CIO hears only if unresolved after 24 hours

Action needed: update RMM platform

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
N-able N-central (you run N-central 2024.1)
Where
RMM platform · production · reachable from the internet
Why it matters
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-18556)
  • CISA confirms CVE-2026-18556 is exploited in the wild (added 2026-08-04).
  • Federal remediation due date: 2026-08-07.
  • Product match is exact: vendor and product names match (100%).
  • Version 2024.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-18556 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Priya Shah and SOC · status to LENA · CIO hears only if unresolved after 24 hours

Action needed: update Mail server

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Synacor Zimbra Collaboration Suite (ZCS) (you run Zimbra Collaboration Suite 10.0)
Where
Mail server · production · reachable from the internet
Why it matters
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating sy…
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-73570)
  • CISA confirms CVE-2026-73570 is exploited in the wild (added 2026-08-21).
  • Federal remediation due date: 2026-08-24.
  • Product match is exact: vendor and product names match (100%).
  • Version 10.0 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-73570 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Remote desktop gateway

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Citrix NetScaler ADC and NetScaler Gateway (you run NetScaler Gateway 14.1)
Where
Remote desktop gateway · production · reachable from the internet
Why it matters
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-8452)
  • CISA confirms CVE-2026-8452 is exploited in the wild (added 2026-08-26).
  • Federal remediation due date: 2026-08-29.
  • Product match is exact: vendor and product names match (100%).
  • Version 14.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-8452 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Branch VPN appliance

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
Where
Branch VPN appliance · production · reachable from the internet
Why it matters
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operati…
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-83548)
  • CISA confirms CVE-2026-83548 is exploited in the wild (added 2026-09-02).
  • Federal remediation due date: 2026-09-05.
  • Product match is exact: vendor and product names match (100%).
  • Version 12.4.3 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-83548 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Branch VPN appliance

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

Question for a person: CISA's text mentions “authenticated attacker”. Does this attack need a person's help?
What is affected
SonicWall SMA1000 Appliances (you run SMA 1000 12.4.3)
Where
Branch VPN appliance · production · reachable from the internet
Why it matters
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-83549)
  • CISA confirms CVE-2026-83549 is exploited in the wild (added 2026-09-02).
  • Federal remediation due date: 2026-09-05.
  • Product match is exact: vendor and product names match (100%).
  • Version 12.4.3 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-83549 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Sam Lee and SOC · status to LENA · CIO hears only if unresolved after 24 hours

Action needed: update Web store

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Adobe Commerce and Magento (you run Magento 2.4.6)
Where
Web store · production · reachable from the internet
Why it matters
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-75650)
  • CISA confirms CVE-2026-75650 is exploited in the wild (added 2026-09-08).
  • Federal remediation due date: 2026-09-11.
  • Product match is exact: vendor and product names match (100%).
  • Version 2.4.6 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-75650 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Priya Shah and SOC · status to LENA · CIO hears only if unresolved after 24 hours

Action needed: update RMM platform

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
N-able N-central (you run N-central 2024.1)
Where
RMM platform · production · reachable from the internet
Why it matters
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-86218)
  • CISA confirms CVE-2026-86218 is exploited in the wild (added 2026-09-08).
  • Federal remediation due date: 2026-09-11.
  • Product match is exact: vendor and product names match (100%).
  • Version 2024.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-86218 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to cio@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update Remote desktop gateway

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Citrix NetScaler (you run NetScaler Gateway 14.1)
Where
Remote desktop gateway · production · reachable from the internet
Why it matters
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-19490)
  • CISA confirms CVE-2026-19490 is exploited in the wild (added 2026-09-09).
  • Federal remediation due date: 2026-09-12.
  • Product match is exact: vendor and product names match (100%).
  • Version 14.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-19490 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Act nowto Dana Ruiz and SOC · status to Marco · CISO hears only if unresolved after 24 hours

Action needed: update HQ VPN gateway

Act now, because it's reachable from the internet, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Fortinet Multiple Products (you run FortiOS 7.2.8)
Where
HQ VPN gateway · production · reachable from the internet
Why it matters
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
When
Start mitigation today. Acknowledge within 2 hours, plan within 8 hours.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2025-25249)
  • CISA confirms CVE-2025-25249 is exploited in the wild (added 2026-09-09).
  • Federal remediation due date: 2026-09-12.
  • Product match is likely: Fortinet advisory names FortiOS in its description.
  • Version 7.2.8 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2025-25249 as exploited in the wild.
  • System Exposure = open: the inventory marks this asset internet-facing.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 70 → immediate. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:O/. Escalates to ciso@acme.example after 24 hours.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Dana Ruiz · status to Marco · CISO hears only if unresolved after 7 days

Action needed: update Wi-Fi controller

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Ubiquiti UniFi OS (you run UniFi OS 4.1)
Where
Wi-Fi controller · production
Why it matters
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-34910)
  • CISA confirms CVE-2026-34910 is exploited in the wild (added 2026-06-23).
  • Federal remediation due date: 2026-06-26.
  • Product match is exact: vendor and product names match (100%).
  • Version 4.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-34910 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Dana Ruiz · status to Marco · CISO hears only if unresolved after 7 days

Action needed: update Wi-Fi controller

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Ubiquiti UniFi OS (you run UniFi OS 4.1)
Where
Wi-Fi controller · production
Why it matters
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-34909)
  • CISA confirms CVE-2026-34909 is exploited in the wild (added 2026-06-23).
  • Federal remediation due date: 2026-06-26.
  • Product match is exact: vendor and product names match (100%).
  • Version 4.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-34909 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Dana Ruiz · status to Marco · CISO hears only if unresolved after 7 days

Action needed: update Wi-Fi controller

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Ubiquiti UniFi OS (you run UniFi OS 4.1)
Where
Wi-Fi controller · production
Why it matters
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-34908)
  • CISA confirms CVE-2026-34908 is exploited in the wild (added 2026-06-23).
  • Federal remediation due date: 2026-06-26.
  • Product match is exact: vendor and product names match (100%).
  • Version 4.1 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-34908 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to ciso@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Intranet portal

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Microsoft SharePoint Server (you run SharePoint Server 2019)
Where
Intranet portal · production
Why it matters
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-45659)
  • CISA confirms CVE-2026-45659 is exploited in the wild (added 2026-07-01).
  • CISA reports use in ransomware campaigns.
  • Federal remediation due date: 2026-07-04.
  • Product match is exact: vendor and product names match (100%).
  • Version 2019 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-45659 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Intranet portal

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Microsoft SharePoint Server (you run SharePoint Server 2019)
Where
Intranet portal · production
Why it matters
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-56164)
  • CISA confirms CVE-2026-56164 is exploited in the wild (added 2026-07-14).
  • Federal remediation due date: 2026-07-17.
  • Product match is exact: vendor and product names match (100%).
  • Version 2019 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-56164 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Intranet portal

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Microsoft SharePoint (you run SharePoint Server 2019)
Where
Intranet portal · production
Why it matters
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-58644)
  • CISA confirms CVE-2026-58644 is exploited in the wild (added 2026-07-16).
  • Federal remediation due date: 2026-07-19.
  • Product match is exact: vendor and product names match (100%).
  • Version 2019 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-58644 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Intranet portal

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Microsoft SharePoint (you run SharePoint Server 2019)
Where
Intranet portal · production
Why it matters
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-50522)
  • CISA confirms CVE-2026-50522 is exploited in the wild (added 2026-07-22).
  • Federal remediation due date: 2026-07-25.
  • Product match is exact: vendor and product names match (100%).
  • Version 2019 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-50522 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Sam Lee · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Build server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy

What is affected
JetBrains TeamCity (you run TeamCity 2024.03)
Where
Build server · staging
Why it matters
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-63077)
  • CISA confirms CVE-2026-63077 is exploited in the wild (added 2026-08-05).
  • Federal remediation due date: 2026-08-08.
  • Product match is exact: vendor and product names match (100%).
  • Version 2024.03 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-63077 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = low: this is a staging system; mission impact is at most degraded.
  • Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update File server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

Question for a person: CISA's text mentions “locally”. Does this attack need a person's help?
What is affected
Microsoft Windows Ancillary Function Driver for WinSock (you run Windows Server 2022)
Where
File server · production
Why it matters
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-68820)
  • CISA confirms CVE-2026-68820 is exploited in the wild (added 2026-08-11).
  • Federal remediation due date: 2026-08-25.
  • Product match is exact: vendor and product names match (100%).
  • Version 2022 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-68820 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Virtualization manager

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a lot.Show me in the policy

What is affected
Broadcom VMware vCenter (you run vCenter Server 8.0u2)
Where
Virtualization manager · production
Why it matters
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-59310)
  • CISA confirms CVE-2026-59310 is exploited in the wild (added 2026-08-18).
  • CISA reports use in ransomware campaigns.
  • Federal remediation due date: 2026-08-21.
  • Product match is exact: vendor and product names match (100%).
  • Version 8.0u2 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-59310 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = high: criticality 'high' in the inventory.
  • Decided by SEI deployer tree (default), row 62 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:H/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Intranet portal

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

What is affected
Microsoft SharePoint (you run SharePoint Server 2019)
Where
Intranet portal · production
Why it matters
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-55040)
  • CISA confirms CVE-2026-55040 is exploited in the wild (added 2026-08-18).
  • Federal remediation due date: 2026-08-21.
  • Product match is exact: vendor and product names match (100%).
  • Version 2019 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-55040 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Security team (no owner on file) · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Print server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy

What is affected
PaperCut NG/MF (you run PaperCut MF 22.1)
Where
Print server · production
Why it matters
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the securit…
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-82078)
  • CISA confirms CVE-2026-82078 is exploited in the wild (added 2026-08-31).
  • Federal remediation due date: 2026-09-14.
  • Product match is exact: vendor and product names match (100%).
  • Version 22.1 was not checked; the CISA feed does not list affected versions.
  • No owner recorded for this asset; routed to the fallback contact.
  • Exploitation = active: CISA lists CVE-2026-82078 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = low: criticality 'low' in the inventory.
  • Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Security team (no owner on file) · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update Print server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt a little.Show me in the policy

What is affected
PaperCut NG/MF (you run PaperCut MF 22.1)
Where
Print server · production
Why it matters
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-81578)
  • CISA confirms CVE-2026-81578 is exploited in the wild (added 2026-08-31).
  • Federal remediation due date: 2026-09-14.
  • Product match is exact: vendor and product names match (100%).
  • Version 22.1 was not checked; the CISA feed does not list affected versions.
  • No owner recorded for this asset; routed to the fallback contact.
  • Exploitation = active: CISA lists CVE-2026-81578 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = low: criticality 'low' in the inventory.
  • Decided by SEI deployer tree (default), row 60 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:L/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update File server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

Question for a person: CISA's text mentions “local attacker”. Does this attack need a person's help?
What is affected
Microsoft Windows (you run Windows Server 2022)
Where
File server · production
Why it matters
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-81963)
  • CISA confirms CVE-2026-81963 is exploited in the wild (added 2026-09-08).
  • Federal remediation due date: 2026-09-22.
  • Product match is exact: vendor and product names match (100%).
  • Version 2022 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-81963 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Update soonto Priya Shah · status to LENA · CIO hears only if unresolved after 7 days

Action needed: update File server

Update soon, because it's reachable only from inside, the attack can run by itself, and it would hurt some.Show me in the policy

Question for a person: CISA's text mentions “locally”. Does this attack need a person's help?
What is affected
Microsoft Windows (you run Windows Server 2022)
Where
File server · production
Why it matters
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
When
Sooner than your normal cycle, at the next available opportunity, and no later than the CISA due date. Acknowledge within 2 days, plan within 7 days.
What to do
Apply mitigations in accordance with vendor instructions.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-85880)
  • CISA confirms CVE-2026-85880 is exploited in the wild (added 2026-09-08).
  • Federal remediation due date: 2026-09-22.
  • Product match is exact: vendor and product names match (100%).
  • Version 2022 was not checked; the CISA feed does not list affected versions.
  • Exploitation = active: CISA lists CVE-2026-85880 as exploited in the wild.
  • System Exposure = controlled: not internet-facing; assumed reachable from the internal network.
  • Automatable = yes: assumed the attack can run by itself, the worst case, until a person says otherwise.
  • Human Impact = medium: criticality 'medium' in the inventory.
  • Decided by SEI deployer tree (default), row 61 → out-of-cycle. SSVC vector SSVCv2/A:Y/E:A/H:M/Se:C/. Escalates to cio@acme.example after 7 days.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Watchto Dana Ruiz

Does this apply? HQ VPN gateway

Watch, because we are not sure this product is the one on this asset.

What is affected
Fortinet FortiSandbox (you run FortiOS 7.2.8)
Where
HQ VPN gateway · production · reachable from the internet
Why it matters
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP reques…
When
No action yet. Tell us whether this product is really in use. Acknowledge within 7 days.
What to do
Tell us whether this product is really in use. If it is, follow the vendor fix.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-25089)
  • CISA confirms CVE-2026-25089 is exploited in the wild (added 2026-07-16).
  • Federal remediation due date: 2026-07-19.
  • Product match is possible: vendor matches; product name only partly matches (63%).
  • Version 7.2.8 was not checked; the CISA feed does not list affected versions.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Watchto Dana Ruiz

Does this apply? HQ VPN gateway

Watch, because we are not sure this product is the one on this asset.

What is affected
Fortinet FortiSandbox (you run FortiOS 7.2.8)
Where
HQ VPN gateway · production · reachable from the internet
Why it matters
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
When
No action yet. Tell us whether this product is really in use. Acknowledge within 7 days.
What to do
Tell us whether this product is really in use. If it is, follow the vendor fix.

Nobody has acted on this yet.

Open official fix
For the auditor (CVE-2026-39808)
  • CISA confirms CVE-2026-39808 is exploited in the wild (added 2026-07-16).
  • Federal remediation due date: 2026-07-19.
  • Product match is possible: vendor matches; product name only partly matches (63%).
  • Version 7.2.8 was not checked; the CISA feed does not list affected versions.
  • CISA's full required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Who would have heard from us, and how much

PersonFull notices, to fixOne-line statusesHears only if stuck
Dana Ruiz dana@acme.example13
SOC soc@acme.example13
Priya Shah priya@acme.example13
CIO cio@acme.example17
CISO ciso@acme.example11
LENA lena@acme.example8
Sam Lee sam@acme.example2
Security team security@example.com2
Marco marco@acme.example4

What the accountable people see

The whole message. No CVE numbers, no descriptions, no links to advisories.

Marco marco@acme.example

3 urgent technology risks need attention

  • Act nowBranch VPN appliance: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Act nowHQ VPN gateway: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Act nowRemote desktop gateway: act now. Assigned to Dana Ruiz. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Update soonWi-Fi controller: update soon. Assigned to Dana Ruiz. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
LENA lena@acme.example

3 urgent technology risks need attention

  • Act nowRMM platform: act now. Assigned to Priya Shah. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Act nowMail server: act now. Assigned to Priya Shah. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Act nowWeb store: act now. Assigned to Sam Lee. Acknowledge within 2 hours, plan within 8 hours. Decision needed from you: none at this time.
  • Update soonIntranet portal: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
  • Update soonBuild server: update soon. Assigned to Sam Lee. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
  • Update soonFile server: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
  • Update soonVirtualization manager: update soon. Assigned to Priya Shah. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.
  • Update soonPrint server: update soon. Assigned to Security team. Acknowledge within 2 days, plan within 7 days. Decision needed from you: none at this time.

Why was this not sent?

CVE-2026-34486 on Legacy app server was not sent because exception on file until 2026-12-31 (behind WAF; replacement scheduled Q4). Owner: Sam Lee.
CVE-2026-20349 on Old lab firewall was not sent because asset is marked 'retired' (row 14). Owner: Dana Ruiz.

Facts come from CISA and the inventory. Estimates are PatchOwner's own matching and mapping and are labeled as such. An estimate never lowers urgency on its own. Versions are never assumed. Decision vocabulary: SSVC v2, SEI/CERT, Carnegie Mellon University.