Skip to content
.ca
sign in

Threat intelligence from CISA

117 reports on cyfar.ca summarizing CISA research. Visit CISA

CISA12 days ago5 minLLM reportmedium

CISA Vulnerability Review (2026-08-26)

CISA published a Vulnerability Review analyzing fiscal year 2024 and 2025 vulnerability data from CISA and open source sources. The review establishes that most compromises result from exploitation of well-known vulnerabilities rather than advanced techniques. It identifies common software weakness patterns, promotes Secure by Design principles, and recommends a risk-based prioritization framework aligned with Binding Operational Directive 26-04 using four criteria: exposure status, KEV Catalog status, automated exploitation potential, and technical impact.

CISA12 days ago6 minLLM reporthigh

PayRange API (CVE-2026-18965)

CISA published an ICS advisory for CVE-2026-18965, a missing authorization vulnerability (CWE-862) in all versions of the PayRange API. The flaw exposes management endpoints without proper access controls, allowing remote attackers to disclose sensitive information about every device on the PayRange network, modify device settings to cause denial of service, or alter displayed images. The CVSS v3.1 score is 8.8 (HIGH). PayRange has not responded to CISA coordination efforts, leaving no vendor-supplied patch available.

CISA13 days ago4 minLLM reporthigh

Rently Smart Home (CVE-2026-75960)

Rently Smart Home versions 20.1.0 and prior contain an insufficiently protected credentials vulnerability (CVE-2026-75960). Exploitation allows an attacker to retrieve sensitive pins, including the Master Pin, and override standard user permissions. The vendor has patched the vulnerability in late June.

CISA13 days ago9 minLLM reportcritical

Ebyte NE2-D11 (CVE-2026-73125, CVE-2026-73809, CVE-2026-73839 +8 more)

CISA published an ICS advisory disclosing eleven vulnerabilities in the Ebyte NE2-D11 industrial gateway device running firmware FW-9167-0-11. Three CVEs are rated CVSS 9.8 Critical, covering missing authentication, client-side authentication bypass, and cleartext MQTT credential transmission. No patch is available; the vendor acknowledged the reports but has not provided remediation. Attackers can exploit these flaws remotely without authentication to gain administrative control, intercept credentials, hijack sessions, and disrupt device operation.

CISA13 days ago11 minLLM reporthigh

A Tale of Two SOCs: Insights From Two Red Team Assessments (2026-08-25)

CISA conducted simultaneous red team assessments at two critical infrastructure organizations using similar tradecraft. The red team achieved full domain compromise at both organizations by exploiting ADCS misconfigurations, excessive Machine Account Quota settings, cleartext credentials, and overly permissive Entra ID application permissions. Organization A failed to detect the activity due to untuned EDR alerts and organizational silos, while Organization B rapidly triaged and isolated compromised systems. Both organizations lacked Conditional Access policies for workload identities and mature processes for revoking compromised cloud tokens.

CISA14 days ago5 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-21962)

CISA has added CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Federal agencies are mandated to remediate this under BOD 26-04, while CISA advises all organizations to prioritize patching. The vulnerability poses significant risks to exposed assets.

CISA17 days ago6 minLLM reportcritical

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-73570)

CISA added CVE-2026-73570, an OS Command Injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed active exploitation. The vulnerability allows attackers to execute arbitrary OS commands on affected hosts. BOD 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on exposed assets and to investigate whether systems were compromised prior to patching.

CISA18 days ago6 minLLM reportmedium

Johnson Controls Simplex Incident Manager (CVE-2026-27875)

Johnson Controls Simplex Incident Manager versions V2.01 and earlier are vulnerable to cleartext storage of sensitive information in memory (CVE-2026-27875). A local attacker with low privileges can extract user credentials and authentication tokens from system memory using memory-dumping tools, potentially leading to unauthorized access to the application and connected systems.

CISA18 days ago5 minLLM reporthigh

CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-72529, CVE-2026-72530)

CISA added two actively exploited TrueConf Server vulnerabilities to the KEV Catalog: CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection). Federal agencies are required by BOD 26-04 to remediate these on publicly exposed assets. CISA recommends all organizations prioritize patching these vulnerabilities.

CISA19 days ago6 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-64849)

CISA added CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability affecting MLflow Server, to its Known Exploited Vulnerabilities Catalog after confirming evidence of active exploitation. The article provides no technical detail on the exploitation method, affected versions, or observed attacker infrastructure, and instead focuses on remediation obligations under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.

CISA19 days ago6 minLLM reporthigh

Defending Against an Active Threat to Siemens S7 Series PLCs (2026-08-19)

Threat actors are actively targeting Siemens S7 Series PLCs using AI-generated exploitation scripts and open-source libraries like snap7.dll. The actors use Internet scanning to find exposed PLCs and masquerade their tools as legitimate monitoring software to conduct reconnaissance and prepare for operational effects. Organizations should patch, segment, and monitor S7comm traffic on TCP port 102 to defend against this activity.

CISA20 days ago6 minLLM reporthigh

CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-33824, CVE-2026-55040, CVE-2026-59310 +1 more)

CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerabilities span Microsoft IKE Service Extensions (double free), Microsoft SharePoint (weak authentication), Broadcom VMware vCenter (path traversal), and Apple macOS (improper authentication). BOD 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation and to check for prior compromise.

CISA20 days ago8 minLLM reporthigh

CISA Malcolm (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134 +3 more)

CISA disclosed six vulnerabilities in the CISA Malcolm network traffic analysis tool suite. The most severe is CVE-2026-55676 (CVSS 8.8), which allows authenticated users with the upload-only role to upload and execute arbitrary PHP code. Two RBAC bypass vulnerabilities (CVE-2026-63177 and CVE-2026-19670) exploit discrepancies between Nginx routing and the Lua RBAC layer's URI normalization. Two denial-of-service vulnerabilities (CVE-2026-63133 and CVE-2026-19671) exploit resource exhaustion during archive extraction. Patches are available across versions 26.06.1, 26.07.0, and 26.08.0.

CISA20 days ago5 minLLM reporthigh

Siemens Simcenter Nastran (CVE-2026-59086)

Siemens Simcenter Nastran and Simcenter Femap versions prior to V2606 are affected by a stack-based buffer overflow vulnerability (CVE-2026-59086). The flaw allows remote code execution in the context of the current process when a user is tricked into running an impacted application binary with a malicious string argument. Siemens has released updates and recommends updating to V2606 or later.

CISA21 days ago4 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2025-62593)

CISA has added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerability poses significant risks to the federal enterprise and is a frequent attack vector for malicious cyber actors. BOD 26-04 requires FCEB agencies to prioritize rapid remediation of such vulnerabilities on publicly exposed assets that grant total control post-exploitation.

CISA25 days ago6 minLLM reportmedium

Siemens Desigo DXR and PXC Controllers (CVE-2026-59693)

Siemens Desigo DXR and PXC building automation controllers contain a denial-of-service vulnerability (CVE-2026-59693) caused by improper handling of malformed BACnet packets. An attacker on the same network segment can send crafted packets that cause affected devices to stop responding to BACnet queries, requiring a manual reset or reboot. Siemens has released firmware updates for all affected product lines.

CISA25 days ago7 minLLM reporthigh

Siemens License Server (SLS) (CVE-2026-69108, CVE-2026-69109)

Siemens License Server (SLS) is affected by two vulnerabilities: a local privilege escalation via an insecure sudoers policy (CVE-2026-69108) and a remote path traversal allowing arbitrary file read (CVE-2026-69109). The privilege escalation could lead to full system compromise by enabling root-level command execution. The path traversal exposes arbitrary files to remote attackers without authentication. Siemens recommends updating to V5.1 or later for the sudoers fix and V5.3 or later for the path traversal fix.

CISA25 days ago5 minLLM reporthigh

Siemens Parasolid (CVE-2026-64629)

Siemens Parasolid V38.0 and V38.1 are affected by an out-of-bounds read vulnerability (CVE-2026-64629) that is triggered when the application parses specially crafted X_T format files. The flaw allows an attacker to crash the application or execute arbitrary code with the privileges of the current process. Siemens has released fixed versions V38.0.235 and V38.1.230.

CISA27 days ago7 minLLM reporthigh

CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-20349, CVE-2026-68820, CVE-2026-72898)

CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The vulnerabilities span Cisco Secure Firewall ASA/FTD (heap inspection), Microsoft Windows AFD WinSock (use-after-free), and Metabase (SQL injection). Federal agencies are required to remediate these on publicly exposed assets under BOD 26-04, and CISA encourages all organizations to prioritize patching.

CISA27 days ago6 minLLM reporthigh

Pulsetto Vagus Nerve Stimulator (CVE-2026-18844)

CISA ICS Medical Advisory ICSMA-26-223-02 discloses CVE-2026-18844, a hidden functionality vulnerability (CWE-912) in all versions of the Pulsetto Vagus Nerve Stimulator. The device firmware processes undocumented Bluetooth Low Energy commands that are sent without authentication or encryption and are never issued by the companion mobile application. An attacker within BLE range could exploit these commands to disable electrical safety mechanisms or alter stimulation parameters, creating a patient safety risk. The vendor has not responded to CISA coordination efforts.