CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
Developer Toolchain Under Siege: Supply Chain and AI Infrastructure
Four of the most recent additions to CISA's Known Exploited Vulnerabilities catalog target the same layer of the stack: the development environment itself. CVE-2026-48027 (Nx Console), CVE-2026-45321 (TanStack), and CVE-2026-8398 (Daemon Tools Lite) all involve malicious code distributed through trusted update mechanisms to developers who did nothing wrong — coordinated pressure on CI/CD infrastructure underscored by CISA's simultaneous "Megalodon" GitHub advisory. A compromised pipeline is a master key: threat actors gain not just access to production systems but to the credentials and secrets that build them. Federal contractors and DevOps teams should treat credential rotation as an immediate operational priority, not a remediation afterthought.
CVE-2026-42271 in BerriAI LiteLLM extends that threat into AI infrastructure specifically. LiteLLM is the routing layer many organizations use to unify access to models like GPT and Claude — and this command injection vulnerability means any authenticated user, including holders of low-privilege internal API keys, can run arbitrary commands on the host. In practice, LiteLLM deployments tend to accumulate API keys broadly and quietly, often without security review. Patch deadline is June 22nd, but given how often this tool runs with elevated host access, treat it as urgent regardless of the calendar.
Deadline Watch: PAN-OS, WebLogic, and SolarWinds
CVE-2026-0257 in Palo Alto Networks PAN-OS and CVE-2024-21182 in Oracle WebLogic Server remain the highest-severity entries in this cycle — both allow unauthenticated attackers to compromise perimeter and application-layer infrastructure respectively, and both deadlines have either passed or are imminent. If your organization hasn't addressed these, the remediation question is no longer just "when to patch" but whether affected systems should be isolated from the network until patching is complete. For vulnerabilities of this class — unauthenticated RCE or auth bypass on internet-facing infrastructure — disconnection pending patch is a legitimate and sometimes necessary remediation path under BOD 22-01, not a last resort.
CVE-2026-28318 in SolarWinds Serv-U rounds out the deadline pressure with a Thursday cutoff. The vulnerability allows unauthenticated attackers to crash the Serv-U file transfer service with a single crafted request — denial of service rather than code execution, but the ability to knock out file transfer infrastructure on demand has real operational consequences. The SolarWinds name warrants attention here even if the severity profile is lower than the RCE entries above.
Sources: CISA KEV Catalog · CISA Advisory: Nx Console / Megalodon · GitHub Security Advisory GHSA-c9j4-9m59-847w · Ox Security: Megalodon · BerriAI LiteLLM CVE-2026-42271 · SolarWinds Serv-U Advisory
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 22-01 deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 22-01
(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks - DataBreaches.Net
IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official ...
An 85-Year-Old Was Told Her Amazon Account Was Hacked. Police Say She Lost $154,000
An 85-year-old Pennsylvania woman was told her Amazon account had been hacked. Police say she later reported losing more than $154000 in a ...
How scammers manipulate our emotions — and what you can do to protect yourself - CBC
Edmonton police working with ethical hackers, U.S. law enforcement to tackle fraud ... A TD Bank customer says he lost $15K to account hacking. The ba...
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of ...
TD Bank holds customer responsible for $15K loss, won't say how account hacking ruled out
A cybersecurity expert says banks are increasingly blaming customers for fraud. When he appealed, the bank said the transactions were conducted using ...
Benn Jordan longs for the days of tech that didn't spy on you | The Verge
In short, Benn Jordan has gone from being one of the best music gear YouTubers to one of the best cybersecurity YouTubers. He was kind enough to ...
Cisco Warns Zero-Day Flaw in SD-WAN is Being Exploited
Cisco warns a zero-day flaw in SD-WAN is being exploited with no current patches available, allowing attackers to conduct command injection attacks.
Chinese APT deploys new malware to keep access to hacked networks
CISA warned about Brickstorm being deployed by Chinese hackers against VMware vSphere servers, and, more recently, Google reported that it was ...
Updated daily
