CISA threat watch

Known exploited vulnerabilities and urgent federal threat notices.

Watch items

Recent CISA watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows ยท sorted newest first

Operations view

WordPress Core Interpretation Conflict Vulnerability

critical
activeCISA KEVCVE-2026-63030

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Jul 20, 2026, 7:00 PMOfficial source

DD-WRT Stack-Based Buffer Overflow Vulnerability

critical
activeCISA KEVCVE-2021-27137

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Jul 20, 2026, 7:00 PMOfficial source

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

critical
activeCISA KEVCVE-2026-0770

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Jul 20, 2026, 7:00 PMOfficial source

WordPress Core SQL Injection Vulnerability

critical
activeCISA KEVCVE-2026-60137

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Jul 20, 2026, 7:00 PMOfficial source

Fortinet FortiSandbox OS Command Injection Vulnerability

critical
activeCISA KEVCVE-2026-39808

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Jul 15, 2026, 7:00 PMOfficial source

Fortinet FortiSandbox OS Command Injection Vulnerability

critical
activeCISA KEVCVE-2026-25089

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Jul 15, 2026, 7:00 PMOfficial source

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

critical
activeCISA KEVCVE-2026-58644

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Jul 15, 2026, 7:00 PMOfficial source

Oracle E-Business Suite Improper Privilege Management Vulnerability

critical
activeCISA KEVCVE-2026-46817

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

Jul 14, 2026, 7:00 PMOfficial source

KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

critical
activeCISA KEVCVE-2023-4346

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

Jul 14, 2026, 7:00 PMOfficial source

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

critical
activeCISA KEVCVE-2026-56164

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

Jul 13, 2026, 7:00 PMOfficial source

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

critical
activeCISA KEVCVE-2026-15409

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Jul 13, 2026, 7:00 PMOfficial source

SonicWall SMA1000 Appliances Code Injection Vulnerability

critical
activeCISA KEVCVE-2026-15410

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Jul 13, 2026, 7:00 PMOfficial source

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

critical
activeCISA KEVCVE-2026-56155

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Jul 13, 2026, 7:00 PMOfficial source

Cisco IOS Cross-Site Request Forgery Vulnerability

critical
activeCISA KEVCVE-2008-4128

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Jul 12, 2026, 7:00 PMOfficial source

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

critical
activeCISA KEVCVE-2026-56291

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

Jul 9, 2026, 7:00 PMOfficial source

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

critical
activeCISA KEVCVE-2026-48939

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Jul 9, 2026, 7:00 PMOfficial source

Adobe ColdFusion Path Traversal Vulnerability

critical
activeCISA KEVCVE-2026-48282

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Jul 6, 2026, 7:00 PMOfficial source

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

critical
activeCISA KEVCVE-2026-55255

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

Jul 6, 2026, 7:00 PMOfficial source

Joomlack Page Builder Improper Access Control Vulnerability

critical
activeCISA KEVCVE-2026-56290

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

Jul 6, 2026, 7:00 PMOfficial source

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

critical
activeCISA KEVCVE-2026-48908

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Jul 6, 2026, 7:00 PMOfficial source

Vendor watch hub

What this page covers

The CISAwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent CISA activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

1651

Active

1651

Featured

1651

Unique CVEs

20

Most recent entry

Jul 20, 2026, 7:00 PM

Feed refreshes daily ยท 5:15 a.m. Central

SourcesยทCISA Known Exploited Vulnerabilities catalog

"Most recent entry" is the newest item the upstream feed has published โ€” not our sync time.

Related vendors

Other research feeds in the radar

Vendor watch FAQ

Common questions

What is the CISA threat watch page?

It is the CISA-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the CISA watch page?

Use it to confirm whether current CISA issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to CISA security issues?

Yes. ITECS can help map CISA advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.