cisa-kev
CISA KEVExtracts: CVE id, vendor, due date · metadata or bounded excerpt
Retention: D1 event history with canonical source link and deduplication metadata.
Access basis: Public endpoint; no project credential required.
Last ingested: 2026-08-26 · run status: success with data
CVE: CVE-2026-48939 Vendor/project: iCagenda Product: iCagenda Known ransomware campaign use: Unknown Due date: 2026-07-13 CWE: CWE-434 iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachm
CVE: CVE-2026-56291 Vendor/project: Balbooa Product: Forms Known ransomware campaign use: Unknown Due date: 2026-07-13 CWE: CWE-434 Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which c