← All articles

CISA KEV

8 articles

CVEAIremediationinfrastructureCISA KEV

CVE-2026-42208: Your AI Gateway Has a SQL Injection. On the Auth Path.

LiteLLM, the proxy that manages your AI API keys, has a pre-auth SQL injection. CVSS 9.8. On CISA KEV. Exploited 36 hours after disclosure. Every API key it stores is compromised.

May 31, 2026
CVEPalo AltoVPNCISA KEV

CVE-2026-0257: Palo Alto GlobalProtect Auth Bypass Now on CISA's Hit List

CISA just added this Palo Alto GlobalProtect vulnerability to the Known Exploited Vulnerabilities catalog. If your VPN runs on PAN-OS, your remote workers might not be the only ones connecting.

May 28, 2026
CVEweb securityremediationsmall businessCISA KEVDrupal

CVE-2026-9082: If Your Website Runs Drupal on PostgreSQL, It's Leaking Data

Anonymous SQL injection in Drupal core. No login required. On CISA KEV. Mass scanning started within days. If you run Drupal on PostgreSQL, patch right now or take it offline.

May 21, 2026
CVEweb securitysmall businessCISA KEV

Your Next.js Auth Middleware Was Decorative This Whole Time

Set one HTTP header and skip all middleware. Authentication, authorization, rate limiting, all of it. CVE-2025-29927. Confirmed exploitation in the wild. If you run Next.js, update now.

May 20, 2026
CVEMicrosoftExchangezero-dayCISA KEV

CVE-2026-42897: Microsoft Exchange Zero-Day Is Being Exploited Right Now

A crafted email is all it takes. Open it in Outlook Web Access and an attacker runs JavaScript in your browser. No patch yet. Here's what to do if you run Exchange on-prem.

May 15, 2026
CVEinfrastructureremediationCISA KEV

Dirty Frag: The Second Linux Root Exploit in Two Weeks

Two new kernel vulnerabilities chain together for race-free root on every major distro. Exploited within 24 hours of disclosure. Same primitive class as Dirty Pipe and CopyFail. Patch your servers.

May 8, 2026
CVEinfrastructureremediationCISA KEV

CVE-2026-31431: 732 Bytes Gets You Root on Every Linux Distro

A 9-year-old kernel bug. 732-byte exploit. Works identically on Ubuntu, RHEL, Debian, Fedora, Amazon Linux. No race condition needed. On CISA KEV. Patch your servers.

May 1, 2026
CVEzero-dayinfrastructureCISA KEV

Ivanti Zero-Days Breached Four Governments Before Anyone Got a Patch

The Dutch data authority. The European Commission. Finland. The Council for the Judiciary. All breached through Ivanti EPMM zero-days. CVSS 9.8. If you manage mobile devices with Ivanti, check your version now.

Feb 3, 2026