Cisa
22 CVEs tracked since 2025. Since Sep 2025, none of them reached CISA KEV.
Cisa CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-09 | 7 | 0 |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | null or fewer | |
| 2026-08 | null or fewer | |
| 2026-09 | 15 | 0 |
Products
The products that kept showing up in Cisa's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cisa.
- CVE-2026-90457The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissi...5.4
- CVE-2026-90456An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into ac...5.4
- CVE-2026-90455A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing compo...5.4
- CVE-2026-90454A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify t...5.4
- CVE-2026-90453A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This ...5.4
- CVE-2026-90452Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker po...5.4
- CVE-2026-90451An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this ...5.4
- CVE-2026-90450The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request h...5.4
- CVE-2026-90449When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's...5.4
- CVE-2026-90448A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route ...5.4
- CVE-2026-90447A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client...5.4
- CVE-2026-90446An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, withou...5.4
- CVE-2026-90445An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination direct...5.4
- CVE-2026-90444A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system com...5.4
- CVE-2026-90443A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthe...5.4
The record
- Peak rank
- #73 in Sep 2026
- Busiest month shown
- Sep 2026, 15 CVEs
- Months with a KEV entry
- 0 since Sep 2025
- Monthly snapshots
- 2 since 2025