This digest compiles five vendor security advisories published by the Canadian Centre for Cyber Security on 2026-07-28, spanning Apache Thrift, Arista VeloCloud Orchestrator, JetBrains TeamCity, Apple's OS/software ecosystem, and Vercel's Next.js framework. The most urgent item is CVE-2026-16812 affecting Arista VeloCloud Orchestrator On-Prem, which CISA added to its Known Exploited Vulnerabilities catalog on July 27, 2026, confirming active exploitation. The remaining advisories describe vendor-disclosed vulnerabilities (decompression bombs, integer overflow, out-of-bounds read, and unspecified fixed issues) without confirmed in-the-wild exploitation at the time of publication.
KEV
28 posts
Cyber Centre Daily Advisory Digest — 2026-07-28 (5 advisories) CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-20253) CISA has added CVE-2026-20253, a missing authentication vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. The vulnerability allows unauthorized access to critical functions, and organizations are strongly advised to prioritize remediation, particularly for publicly exposed assets that could grant total control post-exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-20262, CVE-2026-54420) CISA has added two actively exploited vulnerabilities, CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager and CVE-2026-54420 affecting the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are urged to prioritize remediation of these flaws, particularly on publicly exposed assets, and to investigate for potential pre-patch compromise in alignment with risk-based vulnerability management practices outlined in BOD 26-04.
CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) CISA has added three actively exploited vulnerabilities (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) affecting Arista EOS, Google Chromium V8, and Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these systems to reduce their exposure to ongoing cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-28318) CISA has added CVE-2026-28318, an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247) CISA has added CVE-2026-45247, a deserialization of untrusted data vulnerability affecting the Mirasvit Full Page Cache Warmer, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation, and CISA strongly urges all organizations to prioritize its remediation to reduce exposure to cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595) CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2022-0492, a Linux Kernel improper authentication vulnerability, and CVE-2025-48595, an Android Framework integer overflow vulnerability, citing evidence of active exploitation in the wild.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2024-21182) CISA has added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-42897 CISA has added CVE-2026-42897, a Cross-Site Scripting (XSS) vulnerability in Microsoft Exchange Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation of this flaw to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate this vulnerability per BOD 22-01, and all organizations are strongly urged to prioritize patching to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-0300, an out-of-bounds write vulnerability affecting Palo Alto Networks PAN-OS, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-41940, a missing authentication vulnerability affecting WebPros cPanel, WHM, and WP2, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The flaw allows malicious actors to access critical functions without authentication, posing a significant risk to affected enterprises.
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new actively exploited vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and D-Link DIR-823X devices. Organizations are strongly urged to prioritize patching these flaws, which include path traversal and command injection vectors, to reduce their exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-39987, a Remote Code Execution (RCE) vulnerability in Marimo, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-33825, an insufficient granularity of access control vulnerability in Microsoft Defender, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild.
CISA Adds Eight Known Exploited Vulnerabilities to Catalog CISA has added eight actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, affecting various enterprise software including PaperCut, JetBrains TeamCity, Zimbra, and Cisco Catalyst SD-WAN Manager. Organizations are strongly urged to prioritize remediation of these flaws to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-34197, an improper input validation vulnerability in Apache ActiveMQ, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize patching and remediation to reduce their exposure to cyberattacks.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven actively exploited vulnerabilities affecting Microsoft, Adobe, and Fortinet products to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations to reduce exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-04-07 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding a critical API authentication and authorization bypass vulnerability (CVE-2026-35616) in Fortinet FortiClientEMS. Affecting versions 7.4.5 to 7.4.6, this flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation and requiring immediate patching.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-5281, a Use-After-Free vulnerability in Google Dawn, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2025-53521, a Remote Code Execution vulnerability affecting F5 BIG-IP, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-20131, a deserialization of untrusted data vulnerability affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC), to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-20963, a Microsoft SharePoint Deserialization of Untrusted Data Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation of this flaw as part of their vulnerability management practices to reduce exposure to cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two actively exploited vulnerabilities affecting Google Skia (CVE-2026-3909) and Google Chromium V8 (CVE-2026-3910) to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2025-68613, an Improper Control of Dynamically-Managed Code Resources vulnerability in n8n, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation to reduce exposure to cyberattacks.
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three actively exploited vulnerabilities affecting Omnissa Workspace ONE, SolarWinds Web Help Desk, and Ivanti Endpoint Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to apply patches immediately to mitigate the risk of compromise.
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two actively exploited vulnerabilities, CVE-2026-21385 (Qualcomm Memory Corruption) and CVE-2026-22719 (VMware Aria Operations Command Injection), to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these flaws to reduce exposure to cyberattacks.