WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
critical
activeCISA KEVCVE-2026-0770
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Fortinet FortiSandbox OS Command Injection Vulnerability
critical
activeCISA KEVCVE-2026-39808
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Fortinet FortiSandbox OS Command Injection Vulnerability
critical
activeCISA KEVCVE-2026-25089
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Oracle E-Business Suite Improper Privilege Management Vulnerability
critical
activeCISA KEVCVE-2026-46817
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
critical
activeCISA KEVCVE-2026-56164
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
critical
activeCISA KEVCVE-2026-56155
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
critical
activeCISA KEVCVE-2026-56291
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
critical
activeCISA KEVCVE-2026-48939
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
critical
activeCISA KEVCVE-2026-55255
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Joomlack Page Builder Improper Access Control Vulnerability
critical
activeCISA KEVCVE-2026-56290
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
critical
activeCISA KEVCVE-2026-48908
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Core
criticalCVE-2026-63030
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 8.9% EPSS.
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
DD-WRT
criticalCVE-2021-27137
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 5.4% EPSS.
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Langflow
criticalCVE-2026-0770
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 10.4% EPSS.
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Core
criticalCVE-2026-60137
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 4.0% EPSS.
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
FortiSandbox
criticalCVE-2026-39808
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 84.2% EPSS.
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
FortiSandbox
criticalCVE-2026-25089
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 36.1% EPSS.
Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
E-Business Suite
criticalCVE-2026-46817
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.0% EPSS.
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
KNX Protocol Connection Authorization Option 1
criticalCVE-2023-4346
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.9% EPSS.
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
SharePoint Server
criticalCVE-2026-56164
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 5.6% EPSS.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
SMA1000 Appliances
criticalCVE-2026-15409
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.3% EPSS.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
SMA1000 Appliances
criticalCVE-2026-15410
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.5% EPSS.
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Active Directory Federation Services
criticalCVE-2026-56155
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.4% EPSS.
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
IOS
criticalCVE-2008-4128
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 23.9% EPSS.
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Forms
criticalCVE-2026-56291
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 8.6% EPSS.
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
iCagenda
criticalCVE-2026-48939
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.5% EPSS.
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Langflow
criticalCVE-2026-55255
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.6% EPSS.
Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Page Builder
criticalCVE-2026-56290
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 2.9% EPSS.
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
SP Page Builder
criticalCVE-2026-48908
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.6% EPSS.
The CISAwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent CISA activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
1651
Active
1651
Featured
1651
Unique CVEs
20
Most recent entry
Jul 20, 2026, 7:00 PM
Feed refreshes daily ยท 5:15 a.m. Central
SourcesยทCISA Known Exploited Vulnerabilities catalog
"Most recent entry" is the newest item the upstream feed has published โ not our sync time.
It is the CISA-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the CISA watch page?
Use it to confirm whether current CISA issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to CISA security issues?
Yes. ITECS can help map CISA advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.