The CISAwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent CISA activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
1617
Active
1617
Featured
1617
Unique CVEs
20
Most recent entry
Jun 8, 2026, 7:00 PM
Feed refreshes daily · 5:15 a.m. Central
Sources·CISA Known Exploited Vulnerabilities catalog
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
Watch items
Recent CISA watch items
Showing the 20 most recent items, newest first. Each row links to the official advisory.
20 rows · sorted newest first
Operations view
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
critical
activeCISA KEVCVE-2026-11645
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
critical
activeCISA KEVCVE-2026-20245
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
critical
activeCISA KEVCVE-2026-7473
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Check Point Security Gateway Improper Authentication Vulnerability
critical
activeCISA KEVCVE-2026-50751
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Known ransomware use: Known.
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
critical
activeCISA KEVCVE-2026-45247
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Known ransomware use: Known.
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Known ransomware use: Known.
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
critical
activeCISA KEVCVE-2026-34926
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Microsoft Internet Explorer Use-After-Free Vulnerability
critical
activeCISA KEVCVE-2010-0249
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Chromium V8
criticalCVE-2026-11645
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 5.5% EPSS.
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Catalyst SD-WAN Manager
criticalCVE-2026-20245
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.3% EPSS.
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Extensible Operating System
criticalCVE-2026-7473
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 22.5% EPSS.
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
LiteLLM
criticalCVE-2026-42271
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 60.8% EPSS.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Known ransomware use: Known.
Security Gateway
criticalCVE-2026-50751
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 11.8% EPSS.
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
Serv-U
criticalCVE-2026-28318
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 7.8% EPSS.
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Mirasvit Full Page Cache Warmer
criticalCVE-2026-45247
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 6.1% EPSS.
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
WebLogic Server
criticalCVE-2024-21182
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 89.7% EPSS.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
PAN-OS
criticalCVE-2026-0257
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 58.8% EPSS.
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Known ransomware use: Known.
Nx Console
criticalCVE-2026-48027
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 32.1% EPSS.
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Known ransomware use: Known.
TanStack
criticalCVE-2026-45321
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 17.1% EPSS.
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
cPanel Plugin
criticalCVE-2026-48172
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 8.0% EPSS.
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Core
criticalCVE-2026-9082
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 10.4% EPSS.
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Langflow
criticalCVE-2025-34291
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 32.7% EPSS.
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Apex One
criticalCVE-2026-34926
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.0% EPSS.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Windows
criticalCVE-2008-4250
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 91.8% EPSS.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Internet Explorer
criticalCVE-2010-0249
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 88.8% EPSS.
It is the CISA-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the CISA watch page?
Use it to confirm whether current CISA issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to CISA security issues?
Yes. ITECS can help map CISA advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.