855-TRUSEC-1 (878-7321) [email protected]

Threat awareness

Security insights for better decisions.

Current advisories and confirmed exploitation activity from the U.S. Cybersecurity and Infrastructure Security Agency. Every item links to an authoritative source for full context.

Automatically refreshed every 30 minutes · Source: CISA

Prioritize what attackers use

Recently added exploited vulnerabilities

Open CISA KEV Catalog
CVE-2026-59822

BerriAI · LiteLLM

BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details
CVE-2026-48710

Kludex · Starlette

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication dep…

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details
CVE-2026-49869

Kestra · Kestra OSS

Kestra OSS OS Command Injection Vulnerability

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details
CVE-2026-82329

JFrog · Artifactory

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details
CVE-2026-9586

Sangoma · Switchvox

Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operati…

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details
CVE-2026-83548

SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Recommended action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and C…

Review vulnerability details

Latest intelligence

CISA cybersecurity advisories

All CISA advisories
The live advisory feed is temporarily unavailable. Visit CISA using the link above.

Need help interpreting exposure?

TruSec can help determine whether an advisory applies to your environment and validate the practical risk behind it.

Request A Quote