CISA adds a CVSS 10.0 Oracle WebLogic flaw to its exploited list and gives federal agencies a three-day patch window.
CISA adds four actively exploited flaws covering macOS, SharePoint, vCenter, and Microsoft IKE to its urgent patch catalog.
CISA flags actively exploited TeamCity flaw CVE-2026-63077, giving federal agencies until August 8 to patch.
Langflow, N-able N-central, and Apache Tomcat flaws join the KEV catalog under active exploitation.
CISA's BOD 26-04 requires federal agencies to patch critical exploited vulnerabilities within three days, replacing previous patch directives with a…