#cisa-kev
-
CVE Tracking in 2026: Prioritize When NVD Stops Scoring
NIST moved the NVD to a triage model in April 2026. Here is what CVE tracking and patch prioritization look like when most records never get scored.
-
CVSS 10.0 SD-WAN Bypass: What Emergency Directive 26-03 Signals
CVE-2026-20182 is a maximum-severity authentication bypass in Cisco Catalyst SD-WAN, added to CISA's KEV catalog on May 14 amid active exploitation.
-
This Month in Security: May 2026's Edge-Device Reckoning
May 2026 in review: a CVSS 10.0 Cisco SD-WAN bypass under active exploitation, an exploited Exchange XSS flaw, a critical Exim bug, and a quiet Patch Tuesday.