CVE Tools

Cisa

22 CVEs tracked since 2025. Since Sep 2025, none of them reached CISA KEV.

Cisa CVEs per month

Sep 2025 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cisa CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0970
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-09150

Products

The products that kept showing up in Cisa's monthly top three, with their CVEs summed over those months.

  1. Malcolm151 month
  2. Thorium71 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cisa.

  1. CVE-2026-90457The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissi...5.4
  2. CVE-2026-90456An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into ac...5.4
  3. CVE-2026-90455A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing compo...5.4
  4. CVE-2026-90454A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify t...5.4
  5. CVE-2026-90453A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This ...5.4
  6. CVE-2026-90452Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker po...5.4
  7. CVE-2026-90451An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this ...5.4
  8. CVE-2026-90450The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request h...5.4
  9. CVE-2026-90449When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's...5.4
  10. CVE-2026-90448A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route ...5.4
  11. CVE-2026-90447A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client...5.4
  12. CVE-2026-90446An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, withou...5.4
  13. CVE-2026-90445An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination direct...5.4
  14. CVE-2026-90444A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system com...5.4
  15. CVE-2026-90443A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthe...5.4

The record

Peak rank
#73 in Sep 2026
Busiest month shown
Sep 2026, 15 CVEs
Months with a KEV entry
0 since Sep 2025
Monthly snapshots
2 since 2025
Cisa's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store