Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICISA Issues Fresh SBOM Guidance. Did They Get It Right?
CISA has released updated guidance on Software Bill of Materials (SBOM) that introduces approximately two dozen changes to SBOM fields aimed at improving comprehensiveness. However, critics contend that while the updates enhance data collection, they fall short of delivering meaningful improvements to risk management capabilities.
AICISA Rewrites Federal Patching Requirements for AI Threat Era
CISA has issued updated federal patching requirements that mandate agencies fix critical vulnerabilities within three days, while allowing extended timelines for less severe issues. The directive reflects an adaptation to the evolving threat landscape shaped by AI-enabled attacks and automated exploitation techniques.
AICISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
CISA has added a high-severity denial-of-service vulnerability (CVE-2026-28318) affecting SolarWinds Serv-U file server software to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation in the wild. The flaw, with a CVSS score of 7.5, can cause the service to crash, potentially disrupting critical file transfer operations for enterprise organizations.
AICISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA has added CVE-2026-45247, a critical remote code execution vulnerability in Mirasvit Cache Warmer for Magento, to its Known Exploited Vulnerabilities catalog. The flaw, which has a CVSS score of 9.8, involves deserialization of untrusted data and is being actively exploited in the wild, posing significant risk to e-commerce platforms using this popular full-page cache extension.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-42208, a SQL injection vulnerability in BerriAI LiteLLM, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. While remediation is mandatory for Federal Civilian Executive Branch agencies under BOD 22-01, CISA strongly recommends all organizations prioritize patching these vulnerabilities as part of their vulnerability management practices.
