{ "feed": { "category": [ { "scheme": "urn:ietf:params:rolie:category:information-type", "term": "csaf" } ], "entry": [ { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-251-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-02.json.asc", "rel": "signature" } ], "published": "2026-09-08T18:44:30Z", "title": "Waves Central local privilege escalation via Improper XPC Client Authentication in macOS", "updated": "2026-09-08T18:44:30Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-251-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-01.json.asc", "rel": "signature" } ], "published": "2026-09-08T18:36:54Z", "title": "Maono Link local privilege escalation", "updated": "2026-09-08T18:36:54Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-239-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-239-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-239-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-239-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-239-01.json.asc", "rel": "signature" } ], "published": "2026-08-27T19:51:09Z", "title": "Redis TLS pending-data list use-after-free", "updated": "2026-08-31T19:12:29Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-238-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-238-01.json.asc", "rel": "signature" } ], "published": "2026-08-26T15:21:45Z", "title": "ComfyUI stored XSS and path traversal vulnerabilities", "updated": "2026-08-26T15:21:45Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-237-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json.asc", "rel": "signature" } ], "published": "2026-08-25T16:12:44Z", "title": "Webkul QloApps multiple vulnerabilities", "updated": "2026-08-25T16:12:44Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-233-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-233-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-233-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-233-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-233-01.json.asc", "rel": "signature" } ], "published": "2026-08-21T15:41:33Z", "title": "ONNX symlink-following and path-traversal arbitrary file write", "updated": "2026-08-21T15:41:33Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-232-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-01.json.asc", "rel": "signature" } ], "published": "2026-08-21T14:33:50Z", "title": "Brushfire unauthenticated information disclosure", "updated": "2026-08-21T14:33:50Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-232-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-232-02.json.asc", "rel": "signature" } ], "published": "2026-08-21T14:33:26Z", "title": "Jet Admin Cloud Platform multiple vulnerabilities", "updated": "2026-08-21T14:33:26Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-225-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-225-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-225-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-225-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-225-01.json.asc", "rel": "signature" } ], "published": "2026-08-13T15:14:49Z", "title": "Philips Hue Bridge Pro", "updated": "2026-08-18T20:28:44Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-169-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json.asc", "rel": "signature" } ], "published": "2026-06-18T15:56:50Z", "title": "Webmin multiple vulnerabilities", "updated": "2026-08-11T15:32:46Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-223-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-02.json.asc", "rel": "signature" } ], "published": "2026-08-11T14:55:45Z", "title": "Google Turbinia arbitrary command execution", "updated": "2026-08-11T14:55:45Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-223-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-01.json.asc", "rel": "signature" } ], "published": "2026-08-11T14:40:29Z", "title": "Genkit improper host header validation", "updated": "2026-08-11T14:40:29Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-222-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json.asc", "rel": "signature" } ], "published": "2026-08-10T17:55:37Z", "title": "Metabase SQL injection", "updated": "2026-08-10T17:55:37Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-216-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json.asc", "rel": "signature" } ], "published": "2026-08-04T17:00:43Z", "title": "IxChariot Endpoint buffer overflow", "updated": "2026-08-04T17:00:43Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-212-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.json.asc", "rel": "signature" } ], "published": "2026-08-04T16:59:44Z", "title": "SNOMED International Snowstorm reflected XSS", "updated": "2026-08-04T16:59:44Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-191-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json.asc", "rel": "signature" } ], "published": "2026-07-10T16:36:19Z", "title": "Deloitte AI Assist for Customer multiple vulnerabilities", "updated": "2026-08-04T16:35:20Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-204-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json.asc", "rel": "signature" } ], "published": "2026-07-23T18:12:13Z", "title": "Appriss Insights VINE Application SQL Injection", "updated": "2026-08-04T16:33:52Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-204-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-02.json.asc", "rel": "signature" } ], "published": "2026-07-23T18:24:12Z", "title": "DHIS2 SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read", "updated": "2026-07-23T18:24:12Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-202-03", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json.asc", "rel": "signature" } ], "published": "2026-07-21T19:53:59Z", "title": "FileGator privilege escalation", "updated": "2026-07-21T19:53:59Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-202-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json.asc", "rel": "signature" } ], "published": "2026-07-21T14:39:13Z", "title": "Trezor Safe improper security check in on-device display", "updated": "2026-07-21T14:39:13Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-183-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-183-01.json.asc", "rel": "signature" } ], "published": "2026-07-02T17:50:36Z", "title": "Cloudflare Universal SSL CAA record override", "updated": "2026-07-21T14:32:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-202-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-01.json.asc", "rel": "signature" } ], "published": "2026-07-21T14:24:29Z", "title": "ASUS AURA SYNC driver local privilege escalation", "updated": "2026-07-21T14:24:29Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-197-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-197-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-197-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-197-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-197-01.json.asc", "rel": "signature" } ], "published": "2026-07-16T18:56:28Z", "title": "remorses/genql code injection", "updated": "2026-07-16T18:56:28Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-190-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json.asc", "rel": "signature" } ], "published": "2026-07-09T17:33:36Z", "title": "LibreBooking path traversal", "updated": "2026-07-09T17:33:36Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-190-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-02.json.asc", "rel": "signature" } ], "published": "2026-07-09T17:33:11Z", "title": "Superior Court of California Hearing Reminder Service unauthenticated information disclosure", "updated": "2026-07-09T17:33:11Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-190-03", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json.asc", "rel": "signature" } ], "published": "2026-07-09T15:46:20Z", "title": "Allwinner TV Box TV98 ADB exposed on network", "updated": "2026-07-09T15:46:20Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-188-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json.asc", "rel": "signature" } ], "published": "2026-07-07T00:00:00Z", "title": "FluxInk Color Management Driver local privilege escalation", "updated": "2026-07-07T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-177-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json.asc", "rel": "signature" } ], "published": "2026-06-26T16:08:29Z", "title": "extract-zip unvalidated symlink path traversal", "updated": "2026-06-26T16:08:29Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-169-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-01.json.asc", "rel": "signature" } ], "published": "2026-06-18T15:45:16Z", "title": "U.S. GAO EPDS and CBCA EDS multiple vulnerabilities", "updated": "2026-06-18T15:45:16Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-168-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-168-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-168-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-168-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-168-01.json.asc", "rel": "signature" } ], "published": "2026-06-17T18:58:50Z", "title": "ServerCo getssl ACME shell script path injection", "updated": "2026-06-17T18:58:50Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-121-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json.asc", "rel": "signature" } ], "published": "2026-05-07T00:00:00Z", "title": "CISA manage.get.gov incorrect portfolio administrator privileges", "updated": "2026-06-04T15:31:57Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-155-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-155-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-155-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-155-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-155-01.json.asc", "rel": "signature" } ], "published": "2026-06-04T14:10:30Z", "title": "SQLite sqldiff remote code execution via argument injection", "updated": "2026-06-04T14:10:30Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-152-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-152-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-152-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-152-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-152-01.json.asc", "rel": "signature" } ], "published": "2026-06-01T19:57:37Z", "title": "DeepAI.org CSRF", "updated": "2026-06-01T19:57:37Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-138-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-01.json.asc", "rel": "signature" } ], "published": "2026-05-19T13:33:10Z", "title": "Tyler Technologies Tyler Identity Default Administrative Credentials", "updated": "2026-05-19T13:33:10Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-138-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-02.json.asc", "rel": "signature" } ], "published": "2026-05-19T13:27:24Z", "title": "Technitium DNS Amplification", "updated": "2026-05-19T13:27:24Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-119-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-02.json.asc", "rel": "signature" } ], "published": "2026-04-29T14:27:50Z", "title": "TP-Link WR841N Router multiple vulnerabilities", "updated": "2026-04-29T14:27:50Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-119-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json.asc", "rel": "signature" } ], "published": "2026-04-29T00:00:00Z", "title": "CryptPad unbounded WebSocket frame flood", "updated": "2026-04-29T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-092-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-02.json.asc", "rel": "signature" } ], "published": "2026-04-02T13:54:30Z", "title": "Zscaler Client Connector hard-coded proxy configuration domain", "updated": "2026-04-23T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-097-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-02.json.asc", "rel": "signature" } ], "published": "2026-04-07T20:51:13Z", "title": "IBM Maximo Application Suite Sensitive Tokens without 'Secure' Attribute", "updated": "2026-04-07T20:51:13Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-097-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-097-01.json.asc", "rel": "signature" } ], "published": "2026-04-07T20:50:15Z", "title": "Thales Sentinel LDK Runtime Stored XSS", "updated": "2026-04-07T20:50:15Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-092-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-092-01.json.asc", "rel": "signature" } ], "published": "2026-04-02T17:11:43Z", "title": "Bentley Systems iTwin Platform exposed access token", "updated": "2026-04-02T17:11:43Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-084-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-084-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-084-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-084-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-084-01.json.asc", "rel": "signature" } ], "published": "2026-03-25T00:00:00Z", "title": "Nanoleaf Lines unauthenticated firmware file store", "updated": "2026-04-02T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-076-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-076-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-076-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-076-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-076-01.json.asc", "rel": "signature" } ], "published": "2026-03-17T17:02:32Z", "title": "Multiple IP-KVM Vulnerabilities", "updated": "2026-03-24T17:54:39Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-077-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-077-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-077-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-077-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-077-01.json.asc", "rel": "signature" } ], "published": "2026-03-19T14:47:43Z", "title": "OPEXUS eComplaint and eCase multiple vulnerabilities", "updated": "2026-03-19T14:47:43Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-297-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-297-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-297-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-297-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-297-01.json.asc", "rel": "signature" } ], "published": "2025-10-22T18:45:47Z", "title": "IBM DOORS Next Generation multiple vulnerabilities", "updated": "2026-03-04T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-082-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json.asc", "rel": "signature" } ], "published": "2026-02-23T00:00:00Z", "title": "Census CSWeb multiple vulnerabilities", "updated": "2026-02-23T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-015-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-015-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-015-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-015-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-015-01.json.asc", "rel": "signature" } ], "published": "2026-01-15T19:59:37Z", "title": "NOAA PMEL Live Access Server (LAS) command injection", "updated": "2026-01-15T19:59:37Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-013-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json.asc", "rel": "signature" } ], "published": "2026-01-13T00:00:00Z", "title": "NSecKrnl driver terminates system processes with crafted IOCTL requests", "updated": "2026-01-13T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-008-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-01.json.asc", "rel": "signature" } ], "published": "2026-01-08T16:36:15Z", "title": "OPEXUS eCASE", "updated": "2026-01-08T16:36:15Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-03.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-008-03", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-03.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-03.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-03.json.asc", "rel": "signature" } ], "published": "2026-01-08T00:00:00Z", "title": "Ideagen DevonWay stored XSS", "updated": "2026-01-08T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-26-008-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-02.json.asc", "rel": "signature" } ], "published": "2026-01-07T16:35:11Z", "title": "OPEXUS eComplaint and eCasePortal IDOR", "updated": "2026-01-07T16:35:11Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-352-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json.asc", "rel": "signature" } ], "published": "2025-12-18T00:00:00Z", "title": "BullWall Ransomware Containment and Server Intrusion Protection multiple vulnerabilities", "updated": "2025-12-18T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-345-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-345-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-345-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-345-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-345-01.json.asc", "rel": "signature" } ], "published": "2025-12-12T20:27:47Z", "title": "CISA Software Acquisition Guide Supplier Response Web Tool XSS", "updated": "2025-12-12T20:27:47Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-343-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json.asc", "rel": "signature" } ], "published": "2025-12-10T16:46:41Z", "title": "Windscribe for Linux 'changeMTU' local privilege escalation", "updated": "2025-12-10T16:46:41Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-304-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-02.json.asc", "rel": "signature" } ], "published": "2025-10-31T17:02:13Z", "title": "Restaurant Brands International assistant platform multiple vulnerabilities", "updated": "2025-10-31T17:02:13Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-304-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-01.json.asc", "rel": "signature" } ], "published": "2025-10-31T16:57:24Z", "title": "ELOG multiple vulnerabilities", "updated": "2025-10-31T16:57:24Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-296-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-296-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-296-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-296-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-296-01.json.asc", "rel": "signature" } ], "published": "2025-10-23T00:00:00Z", "title": "Frontier Airlines website publicly available email address validation", "updated": "2025-10-23T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-289-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-289-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-289-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-289-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-289-01.json.asc", "rel": "signature" } ], "published": "2025-10-16T16:43:55Z", "title": "OPEXUS FOIAXpress unauthenticated administrator password reset", "updated": "2025-10-16T16:43:55Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-282-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json.asc", "rel": "signature" } ], "published": "2025-10-09T19:50:00Z", "title": "Newforma Project Center multiple vulnerabilities", "updated": "2025-10-09T19:50:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-280-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json.asc", "rel": "signature" } ], "published": "2025-10-07T22:50:29Z", "title": "OPEXUS FOIAXpress stored XSS", "updated": "2025-10-07T22:50:29Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-273-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-273-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-273-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-273-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-273-01.json.asc", "rel": "signature" } ], "published": "2025-09-30T00:00:00Z", "title": "Microsoft Windows inconsistent driver blocking", "updated": "2025-09-30T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-272-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json.asc", "rel": "signature" } ], "published": "2025-09-29T00:00:00Z", "title": "Medical Informatics Engineering Enterprise Health multiple vulnerabilities", "updated": "2025-09-29T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-265-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-265-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-265-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-265-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-265-01.json.asc", "rel": "signature" } ], "published": "2025-09-22T14:06:13Z", "title": "Airship AI MFA bypass and default credentials vulnerabilities", "updated": "2025-09-22T14:06:13Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-259-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json.asc", "rel": "signature" } ], "published": "2025-09-16T00:00:00Z", "title": "CISA Thorium multiple vulnerabilities", "updated": "2025-09-16T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-258-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-258-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-258-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-258-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-258-01.json.asc", "rel": "signature" } ], "published": "2025-09-15T18:41:08Z", "title": "psPAS does not enforce TLS 1.2 within Get-PASSAMLResponse", "updated": "2025-09-15T18:41:08Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-174-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json.asc", "rel": "signature" } ], "published": "2025-07-31T17:01:09Z", "title": "OPEXUS FOIAXpress Public Access Link (PAL) multiple vulnerabilities", "updated": "2025-09-09T21:12:34Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-252-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-252-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-252-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-252-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-252-01.json.asc", "rel": "signature" } ], "published": "2025-09-09T20:48:26Z", "title": "OPEXUS FOIAXpress Public Access Link (PAL) SQL injection", "updated": "2025-09-09T20:48:26Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-239-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-239-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-239-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-239-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-239-01.json.asc", "rel": "signature" } ], "published": "2025-08-26T00:00:00Z", "title": "Agiloft multiple vulnerabilities", "updated": "2025-08-26T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-219-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json.asc", "rel": "signature" } ], "published": "2025-08-07T00:00:00Z", "title": "Tyler Technologies ERP Pro 9", "updated": "2025-08-07T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-169-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-169-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-169-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-169-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-169-01.json.asc", "rel": "signature" } ], "published": "2025-07-02T20:57:00Z", "title": "Versa Networks Versa Director multiple vulnerabilities", "updated": "2025-07-02T20:57:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-171-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-171-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-171-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-171-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-171-01.json.asc", "rel": "signature" } ], "published": "2025-06-20T00:00:00Z", "title": "ClamAV", "updated": "2025-06-20T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-136-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-136-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-136-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-136-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-136-01.json.asc", "rel": "signature" } ], "published": "2025-05-16T20:14:51Z", "title": "IBM Security Guardium stored cross-site scripting", "updated": "2025-06-16T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-147-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-147-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-147-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-147-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-147-01.json.asc", "rel": "signature" } ], "published": "2025-05-28T20:57:43Z", "title": "Craft CMS stores user-provided content session files", "updated": "2025-05-28T20:57:43Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-148-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-148-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-148-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-148-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-148-01.json.asc", "rel": "signature" } ], "published": "2025-05-28T15:28:55Z", "title": "ZKTeco BioTime multiple vulnerabilities", "updated": "2025-05-28T15:28:55Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-119-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json.asc", "rel": "signature" } ], "published": "2025-04-29T15:59:52Z", "title": "MSP360 Backup insecure filesystem permissions", "updated": "2025-05-19T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-079-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json.asc", "rel": "signature" } ], "published": "2025-03-20T00:00:00Z", "title": "CentralSquare eTRAKiT.Net SQL injection vulnerability", "updated": "2025-05-02T01:11:43Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-120-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-120-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-120-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-120-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-120-01.json.asc", "rel": "signature" } ], "published": "2025-04-30T00:00:00Z", "title": "Commvault Web Server unspecified vulnerability", "updated": "2025-04-30T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-104-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-104-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-104-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-104-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-104-01.json.asc", "rel": "signature" } ], "published": "2025-04-15T13:49:55Z", "title": "SicommNet multiple vulnerabilities", "updated": "2025-04-23T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-262-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-262-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-262-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-262-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-262-01.json.asc", "rel": "signature" } ], "published": "2024-09-23T00:00:00Z", "title": "Planet Fitness Workouts mobile apps do not properly validate TLS certificates", "updated": "2025-02-28T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-017-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-017-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-017-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-017-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-017-01.json.asc", "rel": "signature" } ], "published": "2025-01-16T00:00:00Z", "title": "TrueFiling authorization bypass via user-controlled keys", "updated": "2025-02-20T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-043-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-043-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-043-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-043-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-043-01.json.asc", "rel": "signature" } ], "published": "2025-02-12T19:44:47Z", "title": "Ivanti Connect Secure and Ivanti Policy Secure external file control vulnerability", "updated": "2025-02-20T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-254-02", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json.asc", "rel": "signature" } ], "published": "2024-09-10T16:03:00Z", "title": "TopQuadrant TopBraid EDG Insecure External Password Storage and XXE Vulnerabilities", "updated": "2025-02-13T20:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-022-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-022-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-022-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-022-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-022-01.json.asc", "rel": "signature" } ], "published": "2025-01-23T00:53:24Z", "title": "ECOVACS lawnmower and vacuum vulnerabilities", "updated": "2025-01-23T00:53:24Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-25-021-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json.asc", "rel": "signature" } ], "published": "2025-01-23T00:00:00Z", "title": "Fedora Repository fedoraIntCallUser default credentials and insecure archive extraction", "updated": "2025-01-23T00:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-331-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-331-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-331-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-331-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-331-01.json.asc", "rel": "signature" } ], "published": "2024-11-26T18:15:49Z", "title": "Valor Apps Easy Folder Listing Pro Joomla! extension deserialization vulnerability", "updated": "2024-11-26T18:15:49Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-325-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-325-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-325-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-325-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-325-01.json.asc", "rel": "signature" } ], "published": "2024-11-20T18:33:57Z", "title": "Versa Networks Versa Director insecure default PostgreSQL configuration", "updated": "2024-11-20T18:33:57Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-201-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-201-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-201-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-201-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-201-01.json.asc", "rel": "signature" } ], "published": "2024-07-19T16:00:00Z", "title": "Adminer and AdminerEvo Multiple Vulnerabilities", "updated": "2024-11-14T17:00:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-317-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-317-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-317-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-317-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-317-01.json.asc", "rel": "signature" } ], "published": "2024-11-13T20:32:00Z", "title": "Ivanti Connect Secure and Ivanti Policy Secure Multiple Vulnerabilities", "updated": "2024-11-13T20:32:00Z" }, { "content": { "src": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-01.json", "type": "application/json" }, "format": { "schema": "https://docs.oasis-open.org/csaf/csaf/v2.0/csaf_json_schema.json", "version": "2.0" }, "id": "VA-24-254-01", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-01.json", "rel": "self" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-01.json.sha512", "rel": "hash" }, { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-01.json.asc", "rel": "signature" } ], "published": "2024-09-10T20:08:00Z", "title": "IBM webMethods Integration Multiple Vulnerabilities", "updated": "2024-09-10T20:08:00Z" } ], "id": "cisa-csaf-it-feed-tlp-white", "link": [ { "href": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/cisa-csaf-it-feed-tlp-white.json", "rel": "self" } ], "title": "CISA CSAF IT feed (TLP:WHITE)", "updated": "2026-09-08T20:20:03Z" } }