CISA added ownCloud CVE-2023-49105, a Linux kernel flaw, and JFrog Artifactory to the KEV catalog on 2026-08-27, plus fresh Citrix NetScaler exploitation.
Citrix NetScaler CVE-2026-8452 is now exploited in the wild and on the CISA KEV list, alongside nine new KEV additions including an ownCloud auth bypass.
Microsoft fixed 751 CVEs across 67 updates in August 2026, 108 rated Critical, and one is already being exploited. What to patch first, and why.
Adobe ColdFusion path traversal CVE-2026-48282, CVSS 10 and CISA KEV listed, has EPSS 0.99. Plus SharePoint, Exchange, and a Zimbra campaign to check.
Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8) is on the CISA KEV list alongside Adobe ColdFusion CVE-2026-48282 and two Exchange flaws. Patch these first.
Russian actors are exploiting an unpatched Zimbra zero-day against US and Ukraine targets while Adobe ColdFusion CVE-2026-48282 sits on CISA KEV at CVSS 10.
CISA added Check Point SmartConsole flaw CVE-2026-16232 (CVSS 9.1) to KEV after in-the-wild exploitation, alongside a SharePoint deserialization bug.
CISA added two WordPress Core flaws (CVE-2026-63030, CVE-2026-60137) to KEV on July 21 as wp2shell attacks install webshells.
Run 650+ Microsoft 365, Intune, Defender, Entra ID, and Purview security checks against a free demo tenant, no cost, no agents.
Get startedPatching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.
Deep security commentary and research notes on Microsoft 365, Intune, Defender, Entra ID (logs included), patch state, CVEs, and Purview, plus behind-the-scenes posts on Senserva Trustworthy AI. Longer articles live on Substack: Senserva on Substack and Mark Shavlik's Substack.