Recent changes

Friday, March 13, 2026

Favicon for www.cisa.gov

Apple Use-After-Free Vulnerability Fixed in iOS/iPadOS 17

CISA has added a use-after-free vulnerability (CVE-2023-41974) affecting Apple iOS and iPadOS to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, which could allow an app to execute arbitrary code with kernel privileges, has been fixed by Apple in iOS 17, iPadOS 17, iOS 15.8.7, and iPadOS 15.8.7.

Priority review Notice Cybersecurity
Favicon for www.cisa.gov

VMware Workspace ONE UEM SSRF Vulnerability CVE-2021-22054

CISA has added VMware Workspace ONE UEM console versions to the Known Exploited Vulnerabilities (KEV) catalog due to an SSRF vulnerability (CVE-2021-22054). This vulnerability may allow a malicious actor to gain access to sensitive information.

Priority review Notice Cybersecurity
Favicon for www.cisa.gov

SolarWinds Web Help Desk RCE Vulnerability CVE-2025-26399

CISA has added CVE-2025-26399, a critical remote code execution vulnerability in SolarWinds Web Help Desk, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability affects versions 12.8.7 and below and allows unauthenticated attackers to run commands on the host machine.

Urgent Notice Cybersecurity
Favicon for www.cisa.gov

n8n RCE Vulnerability CVE-2025-68613

CISA has added CVE-2025-68613, a critical Remote Code Execution vulnerability in n8n's workflow evaluation system, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability affects versions prior to 1.120.4, 1.121.1, and 1.122.0 and allows authenticated attackers to execute arbitrary code.

Urgent Notice Cybersecurity
Favicon for www.cisa.gov

Siemens Heliox EV Chargers Vulnerability Advisory

CISA has issued an advisory regarding a vulnerability in Siemens Heliox EV Chargers that could allow unauthorized access. Siemens has released updated versions and recommends immediate updates to mitigate the risk.

Priority review Notice Cybersecurity
Favicon for www.cisa.gov

Siemens SIDIS Prime Vulnerabilities Advisory

CISA has issued an advisory regarding multiple vulnerabilities in Siemens SIDIS Prime versions prior to V4.0.800, affecting components like OpenSSL, SQLite, and Node.js packages. Siemens recommends updating to the latest version to address these high-severity issues.

Priority review Notice Cybersecurity
Favicon for www.cisa.gov

Siemens RUGGEDCOM APE1808 Devices Vulnerabilities

CISA has issued an advisory regarding multiple vulnerabilities affecting Siemens RUGGEDCOM APE1808 devices. These vulnerabilities, related to HTTP request smuggling and authentication bypass, have been assigned high CVSS scores. Siemens recommends updating to the latest version to address these security risks.

Priority review Notice Cybersecurity
Favicon for www.cisa.gov

CISA Advisory: Trane Tracer SC/SC+/Concierge Vulnerabilities

CISA issued an advisory regarding multiple vulnerabilities (CVE-2026-28252, CVE-2026-28253, CVE-2026-28254) affecting Trane Tracer SC, Tracer SC+, and Tracer Concierge systems. Exploitation could lead to sensitive information disclosure, arbitrary command execution, or denial-of-service.

Urgent Notice Cybersecurity

Showing 11–18 of 18 changes

1 2

4 monitored sources

CISA Known Exploited Vulnerabilities (KEV)

Updated 1d ago 7 recent

Regs.gov: Cybersecurity and Infrastructure Security Agency

Updated 7h ago 5 recent

CISA Cybersecurity Advisories

Updated 3d ago 4 recent

CISA ICS-CERT Advisories

Updated 2d ago 2 recent

Get CISA alerts

Daily digest of CISA regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.