CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
Developer Toolchain Under Siege: A Supply Chain Triple-Threat
Three of the six most recent additions to CISA's Known Exploited Vulnerabilities catalog share a common and deeply unsettling trait: the attack surface wasn't a misconfigured server or an unpatched library — it was the developer's own trusted toolchain. CVE-2026-48027 (Nx Console), CVE-2026-45321 (TanStack), and CVE-2026-8398 (Daemon Tools Lite) all involve malicious code embedded or published under trusted identities, then distributed through automatic update mechanisms to developers who did nothing wrong. The Nx Console compromise is particularly notable given CISA's simultaneous advisory on the broader "Megalodon" GitHub CI/CD campaign — these aren't isolated incidents, they're coordinated pressure on the same ecosystem layer.
The pattern here is deliberate targeting of developer trust infrastructure. By poisoning npm packages and VS Code extensions — tools that live inside the development environment itself — threat actors gain access not just to production systems, but to the credentials, tokens, and secrets that build those systems. A compromised CI/CD pipeline is a master key. Federal contractors and any organization operating cloud or DevOps environments should treat credential rotation not as a remediation step but as an immediate operational priority, particularly for any pipeline secrets, API keys, or cloud provider credentials that may have touched an affected environment since mid-May.
Deadline Watch: PAN-OS Auth Bypass and the Compliance Clock
Two other KEVs demand immediate attention. CVE-2026-0257 in Palo Alto Networks PAN-OS is the most operationally urgent entry in this cycle: an authentication bypass that allows attackers to establish unauthorized VPN connections — no credentials required. Palo Alto firewalls and VPN concentrators are perimeter infrastructure, meaning a successful exploit doesn't just compromise one system, it compromises the boundary between your network and everything outside it. The patch deadline is Monday, giving federal agencies and contractors a narrow window before compliance violations compound an already serious exposure. Organizations that haven't patched should treat any recent VPN authentication logs as potentially adversarial and investigate accordingly.
CVE-2026-48172 in the LiteSpeed cPanel Plugin — a privilege escalation that hands root-level access to any authenticated user — also had its patch deadline pass this week, meaning organizations still running vulnerable versions are operating outside federal compliance windows. Shared hosting providers and managed service organizations with cPanel deployments should assume active exploitation is underway.
The Zombie in the Room: Internet Explorer, 2010
Finally: CVE-2010-0249. Yes, 2010. Internet Explorer's use-after-free vulnerability made the KEV catalog this week as a reminder that "deprecated" and "safe" are not synonyms. If any system in your environment still touches IE — embedded in kiosks, legacy intranet apps, or aging Windows builds — there is no patch coming. The only remediation is elimination. The fact that CISA still finds this worth cataloging in 2026 tells you everything about the persistence of legacy attack surface in enterprise environments.
Sources: CISA KEV Catalog · CISA Advisory: Nx Console / Megalodon · GitHub Security Advisory GHSA-c9j4-9m59-847w · Ox Security: Megalodon · StepSecurity: Nx Console Compromise
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 22-01 deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 22-01
(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Could Quantum Computers Crack Crypto Sooner Than Expected? - Coinfomania
Let's uncover why the Quantum Threat could challenge crypto security by 2030 and what it means for investors and blockchain networks.
Fake Google Ads Impersonating Uniswap Drain $400K in Phishing Scam
Fraudulent Google advertisements posing as Uniswap exposed users to phishing websites, stealing wallet credentials and draining at least $400,000 from...
Salt Typhoon Across the Internet: What AIDE Honeypots Reveal About a Persistent State-Linked Campaign
Global Cyber Alliance report reveals that between August 2023 and August 2025, AIDE recorded over 72 million China-origin attack attempts against deco...
Ransomware group 'The Gentlemen' suffers internal breach, exposing operations
The Gentlemen ransomware gang experienced a significant breach of its internal systems in May 2026, with researchers at Check Point Research gaining v...
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
Researcher Chaotic Eclipse released a proof-of-concept exploit for MiniPlasma, a Windows privilege escalation zero-day that allows attackers to gain S...
Nightmare-Eclipse: Six Zero-Days, Six Weeks and One Big Grudge
A rogue security researcher known as Nightmare-Eclipse has released six unpatched Windows zero-day exploits (BlueHammer, RedSun, UnDefend, YellowKey, ...
Scammers are using a fake captcha hack to steal your information - Yahoo! Finance Canada
Hackers are using this insidious scam to get unwitting victims to install malware themselves.
Connecticut Medicaid Portal Hack Affects Thousands - BankInfoSecurity
A hack on a Connecticut Medicaid web portal involving compromised credentials of a healthcare provider has affected the payment account and other ...
Updated daily
