What defenders
need to know now.
CyberKit continuously curates high-signal advisories from authoritative sources and turns them into an operational reading queue. No endless news feed: exposure, impact and action first.
Current priorities
12 high-signal items · refreshed automatically
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability …
Operational take →CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vul…
Operational take →CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabilit…
Operational take →Johnson Controls Inc. Airwall
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized ac…
Operational take →Siemens License Server (SLS)
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (…
Operational take →Siemens Siveillance Video
View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. Th…
Operational take →CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability
Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in th…
Operational take →CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only.
Operational take →CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only.
Operational take →CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability
Corrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only.
Operational take →CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only.
Operational take →CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.
Operational take →Check exposure with inventory and telemetry before enforcement. CyberKit tools help with the next step.