CISA Cybersecurity Directives & Advisories
Material regulatory developments from Cybersecurity and Infrastructure Security Agency are tracked daily by Cresthaven Analytics. Over the last 90 days, 20 material briefs relevant to professionals operating in the technology, ai & competition sector have been published below. Each brief is sourced directly from the primary regulatory feed, summarized for institutional readers, and scored for materiality.
Recent material activity
A selection of recent published briefs; this is not a complete archive.
CISA adds Adobe Commerce and Magento authorization flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27 2026
CISA added CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability allows unauthenticated privilege …
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds WSO2 path traversal vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27, 2026
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability is a path traversal flaw affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gate…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Check Point VPN remote-code-execution flaw to Known Exploited Vulnerabilities catalog with September 25 federal remediation deadline
CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on September 22, 2026. The flaw is an improper certificate validation vulnerability affecting Check Point Security Gateway and Check Point Spark Fi…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds unauthenticated remote-code-execution flaw in Check Point security infrastructure to mandatory federal patch catalog
CISA added CVE-2026-93616, a path traversal vulnerability in Check Point Security Management Server and related products, to the Known Exploited Vulnerabilities catalog on September 22, 2026. The flaw allows an unauthent…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds F5 BIG-IP APM heap-based buffer overflow to Known Exploited Vulnerabilities catalog with federal remediation deadline
CISA added CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP Access Policy Manager, to its Known Exploited Vulnerabilities catalog on September 22, 2026. The vulnerability permits unauthenticated remote code exec…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Arista VeloCloud Orchestrator improper input validation flaw to Known Exploited Vulnerabilities catalog
CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog on September 22, 2026. The vulnerability involves improper input validation in Arista VeloCloud Orchestrator on-premises deployments and permits re…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Linux Kernel TLS vulnerability CVE-2025-39682 to Known Exploited Vulnerabilities catalog with federal remediation deadline
CISA added CVE-2025-39682 to its Known Exploited Vulnerabilities catalog on September 18, 2026, citing an improper condition check in the Linux Kernel TLS receive path. Federal agencies must remediate by September 21, 20…
Read the full CISA Cybersecurity Directives & Advisories brief →US CISA Cybersecurity release pending Cresthaven Analytics full analysis: KEV addition: CVE-2026-53266 — Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)
US CISA Cybersecurity published a regulatory release titled 'KEV addition: CVE-2026-53266 — Linux Kernel (Linux Kernel Out-of-Bounds Write Vulnerability)'. Cresthaven Analytics' full intelligence brief is pending re-anal…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Linux Kernel race condition vulnerability CVE-2025-39964 to Known Exploited Vulnerabilities catalog with federal remediation deadline
CISA added CVE-2025-39964, a race condition vulnerability in the Linux Kernel, to its Known Exploited Vulnerabilities catalog on September 18, 2026. Federal agencies must remediate by September 21, 2026 under Binding Ope…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Acronis Backup privilege-escalation flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 19, 2026
CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on September 16, 2026. The vulnerability involves incorrect default permissions in the Acronis Backup plugin for cPanel and WHM and the Acronis Bac…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Cisco Identity Services Engine privileged-API vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 19 2026
CISA added CVE-2026-76460, a Cisco Identity Services Engine incorrect privileged-API vulnerability, to its Known Exploited Vulnerabilities catalog on September 16, 2026. The vulnerability allows an unauthenticated remote…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds Google Pixel cellular modem privilege-escalation flaw to Known Exploited Vulnerabilities catalog with federal patch deadline
CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog on September 16, 2026. The vulnerability involves improper authorization in the cellular modem of Google Pixel devices. Federal agencies face a rem…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds critical Cisco Secure Email Gateway SQL injection flaw to Known Exploited Vulnerabilities catalog with September 17 federal remediation deadline
CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco AsyncOS for the Secure Email Gateway, to its Known Exploited Vulnerabilities catalog on September 14, 2026. The flaw allows an unauthenticated remote atta…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds GitLab path traversal flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 14 2026
CISA added CVE-2026-85706, a path traversal vulnerability in GitLab Community Edition and Enterprise Edition, to its Known Exploited Vulnerabilities catalog on September 11, 2026. The flaw permits unauthenticated read ac…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds JFrog Artifactory improper authentication flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline
CISA added CVE-2026-42018, an improper authentication vulnerability in JFrog Artifactory, to its Known Exploited Vulnerabilities catalog on September 11, 2026. The flaw returns an internal anonymous-user token to an unau…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds JFrog Artifactory privilege-escalation flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 25, 2026
CISA added CVE-2026-42016, an incorrect authorization vulnerability in JFrog Artifactory, to its Known Exploited Vulnerabilities catalog on September 11, 2026. The flaw enables privilege escalation through improper valid…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds ConnectWise ScreenConnect privilege-escalation flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 14, 2026
CISA added CVE-2026-84869, an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities catalog on September 11, 2026. The listing sets a f…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds MikroTik RouterOS authentication-bypass flaw to Known Exploited Vulnerabilities catalog with federal patch deadline
CISA added CVE-2026-67277, a missing-authentication vulnerability in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog on September 10, 2026. The flaw enables kernel memory disclosure and denial of servic…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds MikroTik RouterOS privilege-escalation flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 13 2026
CISA added CVE-2026-86060, an improper argument-delimiter neutralization vulnerability in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog on September 10, 2026. Federal agencies face a remediation deadl…
Read the full CISA Cybersecurity Directives & Advisories brief →CISA adds critical Cisco firewall authentication bypass to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 12 2026
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026. The vulnerability affects Cisco Secure Firewall Management Center and Security Cloud Control, allowing an unauthenticated rem…
Read the full CISA Cybersecurity Directives & Advisories brief →
Get every CISA Cybersecurity Directives & Advisories brief delivered the day it lands
From $149/month
Cresthaven Analytics monitors Cybersecurity and Infrastructure Security Agency continuously, applying institutional materiality scoring to every release. Subscribers receive structured briefs via email, portal, and (Professional tier and above) real-time alerts.
View all tiers →