Back to Blog

Cisa Kev

5 articles on this topic.

Vulnerabilities & Mobile Security1 October 2026

Apple patches CoreGraphics zero-day CVE-2026-86950 exploited in targeted attacks

Apple has fixed an out-of-bounds write in Core Graphics that could give code execution from a malicious file. Apple says it may have been used in an "extremely sophisticated attack" on specific individuals, and CISA has added it to KEV.

applezero-daycve-2026-86950
3 min readRead
Vulnerabilities & Exploitation29 September 2026

Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack

CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.

citrixnetscalerzero-day
3 min readRead
Vulnerabilities & Threat Intel20 September 2026

CISA KEV adds Cisco ISE and Acronis Backup flaws: what defenders should patch first

CISA has added CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog. Both sit in infrastructure that attackers value: network access control and backup.

cisa-kevcisco-iseacronis
3 min readRead
Vulnerability Management3 September 2026

CISA Adds Seven Actively Exploited Flaws to KEV — Shells and Miners Follow

A fresh CISA KEV batch spans SonicWall, Sangoma, JFrog, Kestra and LiteLLM — and in several cases the exploitation has already moved past initial access to reverse shells and cryptomining.

cisa-kevvulnerability-managementsonicwall
4 min readRead
Vulnerability Management18 August 2026

CISA KEV Alert: Ray's Browser-Triggered RCE Flaw Is Now Actively Exploited

A critical Ray vulnerability lets a malicious webpage hijack a developer's local AI cluster through DNS rebinding — CISA's KEV listing confirms it's no longer theoretical.

raycisa-kevai-infrastructure
4 min readRead