The CISAwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent CISA activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
1590
Active
1590
Featured
1590
Unique CVEs
20
Most recent entry
May 7, 2026, 7:00 PM
Feed refreshes daily · 5:15 a.m. Central
Sources·CISA Known Exploited Vulnerabilities catalog
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
Watch items
Recent CISA watch items
Showing the 20 most recent items, newest first. Each row links to the official advisory.
20 rows · sorted newest first
Operations view
BerriAI LiteLLM SQL Injection Vulnerability
critical
activeCISA KEVCVE-2026-42208
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
critical
activeCISA KEVCVE-2026-6973
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
critical
activeCISA KEVCVE-2026-41940
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Known ransomware use: Known.
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
critical
activeCISA KEVCVE-2026-33825
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. Known ransomware use: Known.
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. Known ransomware use: Known.
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
critical
activeCISA KEVCVE-2026-20128
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
critical
activeCISA KEVCVE-2026-20133
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
critical
activeCISA KEVCVE-2026-20122
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
critical
activeCISA KEVCVE-2025-32975
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.
LiteLLM
criticalCVE-2026-42208
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.1% EPSS.
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Endpoint Manager Mobile (EPMM)
criticalCVE-2026-6973
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 5.0% EPSS.
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
PAN-OS
criticalCVE-2026-0300
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 4.7% EPSS.
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Known ransomware use: Known.
cPanel & WHM and WP2 (WordPress Squared)
criticalCVE-2026-41940
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 64.3% EPSS.
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
ScreenConnect
criticalCVE-2024-1708
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 84.0% EPSS.
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
DIR-823X
criticalCVE-2025-29635
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 66.8% EPSS.
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
SimpleHelp
criticalCVE-2024-57726
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 49.2% EPSS.
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
SimpleHelp
criticalCVE-2024-57728
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 59.3% EPSS.
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Marimo
criticalCVE-2026-39987
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 78.7% EPSS.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
Defender
criticalCVE-2026-33825
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 4.9% EPSS.
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. Known ransomware use: Known.
NG/MF
criticalCVE-2023-27351
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 87.0% EPSS.
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. Known ransomware use: Known.
TeamCity
criticalCVE-2024-27199
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 91.4% EPSS.
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
Catalyst SD-WAN Manager
criticalCVE-2026-20128
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.0% EPSS.
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
Catalyst SD-WAN Manager
criticalCVE-2026-20133
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.3% EPSS.
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Catalyst SD-WAN Manger
criticalCVE-2026-20122
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.1% EPSS.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
KACE Systems Management Appliance (SMA)
criticalCVE-2025-32975
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 46.5% EPSS.
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Kentico Xperience
criticalCVE-2025-2749
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 3.8% EPSS.
It is the CISA-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the CISA watch page?
Use it to confirm whether current CISA issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to CISA security issues?
Yes. ITECS can help map CISA advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.