CISA threat watch

Known exploited vulnerabilities and urgent federal threat notices.

Vendor watch hub

What this page covers

The CISAwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent CISA activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

1617

Active

1617

Featured

1617

Unique CVEs

20

Most recent entry

Jun 8, 2026, 7:00 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA Known Exploited Vulnerabilities catalog

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent CISA watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

critical
activeCISA KEVCVE-2026-11645

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Jun 8, 2026, 7:00 PMOfficial source

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

critical
activeCISA KEVCVE-2026-20245

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

Jun 8, 2026, 7:00 PMOfficial source

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

critical
activeCISA KEVCVE-2026-7473

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

Jun 8, 2026, 7:00 PMOfficial source

BerriAI LiteLLM Command Injection Vulnerability

critical
activeCISA KEVCVE-2026-42271

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

Jun 7, 2026, 7:00 PMOfficial source

Check Point Security Gateway Improper Authentication Vulnerability

critical
activeCISA KEVCVE-2026-50751

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Known ransomware use: Known.

Jun 7, 2026, 7:00 PMOfficial source

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

critical
activeCISA KEVCVE-2026-28318

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

Jun 4, 2026, 7:00 PMOfficial source

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

critical
activeCISA KEVCVE-2026-45247

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

Jun 2, 2026, 7:00 PMOfficial source

Linux Kernel Improper Authentication Vulnerability

critical
activeCISA KEVCVE-2022-0492

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

Jun 1, 2026, 7:00 PMOfficial source

Android Framework Integer Overflow Vulnerability

critical
activeCISA KEVCVE-2025-48595

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

Jun 1, 2026, 7:00 PMOfficial source

Oracle WebLogic Server Unspecified Vulnerability

critical
activeCISA KEVCVE-2024-21182

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

May 31, 2026, 7:00 PMOfficial source

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

critical
activeCISA KEVCVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

May 28, 2026, 7:00 PMOfficial source

Nx Console Embedded Malicious Code Vulnerability

critical
activeCISA KEVCVE-2026-48027

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Known ransomware use: Known.

May 26, 2026, 7:00 PMOfficial source

TanStack Unspecified Vulnerability

critical
activeCISA KEVCVE-2026-45321

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Known ransomware use: Known.

May 26, 2026, 7:00 PMOfficial source

Daemon Tools Lite Embedded Malicious Code Vulnerability

critical
activeCISA KEVCVE-2026-8398

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

May 26, 2026, 7:00 PMOfficial source

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

critical
activeCISA KEVCVE-2026-48172

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

May 25, 2026, 7:00 PMOfficial source

Drupal Core SQL Injection Vulnerability

critical
activeCISA KEVCVE-2026-9082

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

May 21, 2026, 7:00 PMOfficial source

Langflow Origin Validation Error Vulnerability

critical
activeCISA KEVCVE-2025-34291

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

May 20, 2026, 7:00 PMOfficial source

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

critical
activeCISA KEVCVE-2026-34926

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

May 20, 2026, 7:00 PMOfficial source

Microsoft Windows Buffer Overflow Vulnerability

critical
activeCISA KEVCVE-2008-4250

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

May 19, 2026, 7:00 PMOfficial source

Microsoft Internet Explorer Use-After-Free Vulnerability

critical
activeCISA KEVCVE-2010-0249

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

May 19, 2026, 7:00 PMOfficial source

Related vendors

Other research feeds in the radar

Vendor watch FAQ

Common questions

What is the CISA threat watch page?

It is the CISA-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the CISA watch page?

Use it to confirm whether current CISA issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to CISA security issues?

Yes. ITECS can help map CISA advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.