• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Greenbone AG

Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor

Blog

Users appreciate when software can easily integrate into their existing IT environment. For vendors, this means supporting a cross-platform mix of operating systems and infrastructure. Greenbone is excited to expand our virtualization platform support, bringing Nutanix AHV into our family of supported hypervisors. This addition adds flexibility for deploying OPENVAS SCAN and extends Greenbone’s already diverse support for hypervisors that also includes Microsoft Hyper-V, Oracle VirtualBox, VMware vSphere (ESXi) and and Workstation Pro, Huawei FusionCompute, and Proxmox VE. Our wide range of hypervisor support ensures that defenders can run our solution in virtually any IT environment.

A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for vulnerabilities and stay ahead of cyber attacks. For a full breakdown of our product offerings, check out our solution comparison.

In the rest of this article, we will discuss how to integrate OPENVAS SCAN virtual appliances on the Nutanix AHV Type-1 hypervisor.

OPENVAS SCAN now on Nutanix AHV

The OPENVAS SCAN Virtual Appliance Now Supports the Nutanix AHV Type-1 Hypervisor

Greenbone is excited to add support for Nutanix AHV virtualization. AHV (short for Acropolis Hypervisor) is the native hypervisor of the Nutanix Cloud Infrastructure platform. As a Type-1 hypervisor, AHV runs directly on the host’s hardware. This puts virtualized appliances closer to the underlying hardware and delivers high performance, low latency operation. The overall impact is a faster and more reliable virtualization environment. By contrast, Type-2 hypervisors run on top of a standard desktop operating system, which is not optimized for efficiency and reliability.

Nutanix is built on top of the Linux kernel’s KVM hypervisor and QEMU hardware emulator. The same open-source virtualization stack that underpins much of the modern data center and public cloud. Unlike traditional hypervisors, AHV is included at no additional licensing cost with the Nutanix Cloud Infrastructure platform and is managed through Nutanix Prism.

Whether you are an existing Greenbone enterprise customer looking for new virtualization options, or already running Nutanix AHV and seeking support, Greenbone now has you covered.

How to Set up OPENVAS SCAN on Nutanix AHV

Customers can request a Nutanix-ready instance of the OPENVAS SCAN virtual appliance from a member of the Greenbone sales team. This specialized image is delivered in the QEMU Copy-On-Write (QCOW) format, optimized for Nutanix AHV. Once you receive the .qcow file, complete the following steps in Nutanix Prism to install and configure the OPENVAS SCAN virtual appliance:

  1. Log in to the Nutanix AHV web interface and open the settings menu in the upper right corner.
  2. Select Image Configuration and click Upload Image. Give the image a name, set Image Type to DISK, choose Upload a file, select the QCOW file of the appliance, and click Save.
  3. Switch to the VM view from the drop-down menu in the upper left corner and click Create VM.
  4. Enter a name for the virtual machine, then set the number of virtual CPUs and cores, the amount of memory, and select UEFI as the boot configuration. The appliance requires the EFI/UEFI boot mode.
  5. Click Add New Disk, select Clone from Image Service as the operation, choose SATA as the bus type, select the image you uploaded in step 1, and click Add.
  6. Under Network Adapters (NIC), click Add New NIC and add at least one network interface, then click Save. The import can take up to 10 minutes.
  7. Once imported, select the appliance from the Table tab, click Power on, and complete the OPENVAS SCAN setup process.

Note

When using the community edition of Nutanix AHV, the combination of UEFI and the default network interface can cause issues at startup. As a workaround, add an e1000 network interface via SSH on the Nutanix host:

$ acli vm.nic_create NAMEOFVIRTUALMACHINE model=e1000 network=NAMEOFNETWORK

Full step-by-step instructions, including screenshots, are available in the Greenbone documentation.

Which Hypervisors Does the OPENVAS SCAN Virtual Appliance Support?

Here is an overview of the supported hypervisors and resource requirements for the OPENVAS SCAN virtual appliance.

The OPENVAS SCAN virtual appliance requires the following resources:

  • 2 virtual CPUs
  • 12 GB RAM
  • 500 GB virtual hard disk (can be dynamically allocated)

Hypervisors officially supported by the OPENVAS SCAN virtual appliance, with Type-1 and Type-2 classification and the newly added Nutanix AHV

Appliance resources 2 virtual CPUs | 12 GB RAM | 500 GB virtual disk
Nutanix AHV New
v6.8 or higher

Type-1 hypervisor

Proxmox VE
v8.0 or higher

Type-1 hypervisor

VMware vSphere (ESXi)
v7.0 or higher

Type-1 hypervisor

Huawei FusionCompute
v8.0

Type-1 hypervisor

Microsoft Hyper-V
Server 2016+ (gen 2 VM, config v8.0+)

Type-1 hypervisor

Oracle VirtualBox
v7.0 or higher

Type-2 hypervisor

VMware Workstation Pro
v17.0 or higher

Type-2 hypervisor

Summary

Greenbone has added support for deploying our OPENVAS SCAN virtual appliance on the Nutanix AHV Type-1 hypervisor, giving adding to our industry leading flexibility. This new capability extends the virtualization options, ensuring users can confidently integrate OPENVAS SCAN into any IT environment — including the growing number of data centers built on Nutanix. A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for emerging threats and stay ahead of cyber attacks.

 

Contact Test Now Buy Here Back to Overview
20. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-20 14:29:332026-07-20 14:29:33Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor
Joseph Lee

CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway

Blog

Update

CVE-2026-8452 has now been added to CISA’s KEV list due to active exploitation observed by Previdian (formerly KEVInel) and Defused Cyber. No attribution has been made for the attacks. Attackers were observed installing web shells [T1505.003] for remote command execution and reconnaissance [TA0007]. A full technical write-up and proof-of-concept exploit have been published by watchTowr Labs, increasing the risk of additional attacks.

Citrix security advisory CTX696604 covers six vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. NetScaler Gateway is used to authenticate remote users and connect them to internal network resources, and NetScaler ADC load balancing is a core feature used to distribute requests and improve availability. The highest-risk issues in the bulletin can lead to memory overread, denial of service (DoS), and arbitrary file read. However, specific configurations must be present for the flaws to be exploitable.

The bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. Citrix cloud services have already been upgraded by Citrix. In some cases, exploitation requires specific deployments or enabled features, such as SAML IDP, Gateway services, AAA virtual server exposure, Oracle or DNS roles, management access on NSIP or SNIP, and protocol options attached to virtual servers or services.

There is no evidence of active exploitation for the CVEs included in the CTX696604 advisory, and no public proof-of-concept (PoC) exploits have been released. However the same affected products were actively exploited in March, 2026. In total, Citrix Netscaler has been added to CISA’s KEV list 22 times since late 2021, shockingly 7 times associated with ransomware attacks. Multiple national CERT alerts have been issued for the new CVEs, indicating a high level of global risk [1][2][3][4][5][6][7][8][9][10][11][12][13].

CTX696604 advisory: multiple new vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

The OPENVAS ENTERPRISE FEED includes a remote banner check that identifies vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerability Details for Citrix Bulletin CTX696604

The six CVEs in the bulletin can cause memory overread, DoS, and arbitrary file read. In each case, the vendor ties exploitability to a specific configuration, which narrows exposure but does not eliminate the need for patching. The most operationally sensitive issues are those that are unauthenticated and network-reachable.

The six CVEs disclosed in Citrix advisory CTX696604, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-8452 CVSS 9.8 · Critical EPSS 0.5% (39th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw that can result in unexpected behavior or denial-of-service. The flaw affects devices using SSL VPN, ICA Proxy, CVPN, RDP Proxy, or an AAA virtual server.

CVE-2026-8655 CVSS 9.8 · Critical EPSS 0.5% (40th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw affecting NetScaler ADC only when configured as an Oracle or DNS proxy load balancer, or as a recursive DNS resolver, leading to unexpected behavior or denial-of-service.

CVE-2026-8451 CVSS 7.5 · High EPSS 15.7% (97th)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can disclose sensitive information. The flaw only affects NetScaler ADC or NetScaler Gateway when configured as a SAML identity provider.

CVE-2026-10816 CVSS 7.5 · High EPSS 0.4% (34th)

An unauthenticated, remotely exploitable external control of file name or path [CWE-73] flaw enabling arbitrary file read. Requires access to the NetScaler IP, Cluster Management IP, or subnet IP address with management access enabled.

CVE-2026-10817 CVSS 7.5 · High EPSS 0.4% (34th)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can result in arbitrary file read and potential disclosure of sensitive information. Only affects configurations where TCP Timestamp is enabled in a TCP profile attached to a virtual server or service.

CVE-2026-13474 CVSS 7.5 · High EPSS 0.5% (38th)

An unauthenticated, remotely exploitable denial-of-service [CWE-401] triggered by malformed HTTP/2 requests. Only affects configurations where HTTP/2 is enabled in an HTTP profile attached to an affected virtual server or service.

CVE-2026-8452 and CVE-2026-8655 are both potentially high-impact, remotely exploitable flaws that do not require authentication. They both affect service endpoints that are typically unrestricted. CVE-2026-8451 can result in the disclosure of sensitive information that could be leveraged in subsequent attacks. While CVE-2026-10816 is also remotely exploitable without authentication, management access to the affected device must be enabled.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Affected Products and Versions

The advisory affects multiple customer-managed NetScaler product lines, including standard releases and FIPS or NDcPP builds. According to the vendor, Secure Private Access Hybrid deployments using NetScaler instances are also affected. The impact is configuration-dependent, so defenders should validate both version status and whether the listed services or profiles are enabled.

Product Affected versions Fixed version

NetScaler ADC and NetScaler Gateway

14.1 before 14.1-72.61; 13.1 before 13.1-63.18

14.1-72.61; 13.1-63.18

NetScaler ADC FIPS

before 14.1-72.61 FIPS

14.1-72.61 FIPS

NetScaler ADC FIPS and NDcPP

before 13.1-37.272

13.1-37.272

Mitigating Citrix NetScaler CVEs from Bulletin CTX696604

The fixed releases listed by the vendor in the table above provide the most effective remediation path. Organizations running affected devices should move to the corresponding fixed version for their release train. No workarounds are described in the vendor bulletin.

For CVE-2026-13474, the Cyber Security Agency of Singapore recommends setting the Http2SmallWndTimeout parameter to 30 seconds as an added mitigation. That guidance is specific to the HTTP/2-related issue and does not replace the vendor fix.

Defenders should check whether the affected features are enabled, because the vulnerable conditions depend on deployment state. Security teams should validate SAML IDP configurations; Gateway and AAA virtual servers; Oracle and DNS roles; management access exposure on NSIP or SNIP; TCP Timestamp settings in profiles; and HTTP/2 settings in HTTP profiles. Where those functions are not required, disabling them reduces exposure while patching is scheduled.

Summary

The Citrix CTX696604 advisory describes six NetScaler ADC and NetScaler Gateway vulnerabilities that affect customer-managed deployments and certain Secure Private Access Hybrid instances. The highest-risk CVEs are configuration-dependent. However, these include unauthenticated network-reachable impacts such as unexpected behavior, sensitive information disclosure, DoS, and arbitrary file read conditions. Available evidence does not indicate active exploitation or that a public PoC exists. However, multiple national CERT alerts have been issued for the CVEs [1][2][3][4][5][6][7][8][9][10][11][12][13].

Organizations should scan their infrastructure for affected appliances, confirm whether the vulnerable features are enabled, and apply the fixed releases for their product line without delay. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
16. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-16 15:43:262026-08-31 09:45:46CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway
Joseph Lee

BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access

Blog

BeyondTrust advisory BT26-03, issued on July 6th, 2026, describes multiple new vulnerabilities in BeyondTrust Remote Support (RS) and BeyondTrust Privileged Remote Access (PRA). The vulnerabilities include two critical flaws exploitable without authentication and additional high-severity issues in network communication and web application components. All the flaws require specific configurations for exploitation, but BeyondTrust has not disclosed the configuration details.

According to BeyondTrust, the issues were found through internal AI-driven vulnerability research using publicly available AI models, and they were fixed before exploitation. The vendor also claims that the flaws were not exploited or known outside the company prior to remediation.

BeyondTrust BT26-03-Security-Bulletin: critical and high severity flaws in Remote Support and Privileged Remote Access

There is no evidence that any of the CVEs have been exploited in the wild, and no public proof-of-concept (PoC) exploits have been published. CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024, indicating that the products are popular targets for attackers. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts [1][2][3][4][5][6][7][8][9], indicating high global risk.

BeyondTrust BT26-03 advisory: critical and high-severity vulnerabilities in Remote Support and Privileged Remote Access

OPENVAS ENTERPRISE FEED includes a remote banner version check covering CVE-2026-40138, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust PRA, and a separate remote banner version check for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust RS. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerabilities Disclosed in the BeyondTrust BT26-03 Advisory

The BeyondTrust BT26-03 advisory covers two critical and two high-severity CVEs across two products: BeyondTrust RS and PRA. There is no evidence of exploitation in the wild, and no publicly available PoC exploits exist for any of the CVEs disclosed in BT26-03. All of the flaws have been assigned moderate EPSS scores: 36th – 48th percentiles.

The four CVEs disclosed in BeyondTrust BT26-03, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-40141 CVSS 9.9 · Critical EPSS 0.5% (40th)

An improper neutralization of special elements in data-query logic [CWE-943] flaw in a web application component of BeyondTrust RS and PRA. An authenticated attacker with specific permissions could access or manipulate resources and data outside the intended authorization boundary.

CVE-2026-40139 CVSS 9.8 · Critical EPSS 0.7% (48th)

An improper authentication [CWE-287] flaw in BeyondTrust RS. A remote, unauthenticated attacker could bypass access controls when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40138 CVSS 8.1 · High EPSS 0.4% (36th)

An improper authentication [CWE-287] flaw in BeyondTrust RS and PRA. A remote, unauthenticated attacker could bypass access controls and reach elevated accounts when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40140 CVSS 7.5 · High EPSS 0.6% (44th)

An uncontrolled resource consumption [CWE-400] flaw in the network communication subsystem of BeyondTrust RS and PRA. A remote, unauthenticated attacker could trigger a denial-of-service and disrupt appliance availability.

Affected Products and Versions

BeyondTrust states that all cloud-hosted RS and PRA instances were patched as of April 21st, 2026. For self-hosted deployments, the vendor directs customers to apply the April security rollup patch or upgrade to the fixed product versions. The supplied evidence identifies RS 25.3.2 and earlier and PRA 25.3.2 and earlier as affected. BeyondTrust provides no workarounds for the vulnerabilities.

Product CVEs Affected versions Fixed versions

BeyondTrust Remote Support

CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141

RS 25.3.2 or earlier

RS 25.3.3 or later; Security Rollup April 2026 25 RS or Security Rollup April 2026 24 RS, depending on the RS version

BeyondTrust Privileged Remote Access

CVE-2026-40138, CVE-2026-40140, CVE-2026-40141

PRA 25.3.2 or earlier

PRA 25.3.3 or later; Security Rollup April 2026 25 PRA or Security Rollup April 2026 24 PRA, depending on the PRA version

BeyondTrust Remote Support (RS) is an enterprise-grade remote support tool used by IT service desks, help desks, and support teams to connect to and control remote systems and devices. In operational terms, that means the product often sits on a path used for remote troubleshooting, administrative support, and endpoint interaction.

BeyondTrust Privileged Remote Access (PRA) is used to manage remote access to critical systems for privileged users and third-party vendors. The product includes session monitoring, auditing, recording, and least-privilege controls. BeyondTrust also describes the B Series Appliance as the central communication point for secure remote access, handling session brokering, authentication, logging, auditing, and encryption.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes remote banner version checks for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 across BeyondTrust RS [1] and PRA [2]. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Summary

BT26-03 consolidates four confirmed vulnerabilities across BeyondTrust Remote Support and BeyondTrust Privileged Remote Access. The most important issues are the two critical pre-authentication flaws, followed by the high-severity vulnerabilities in the network communication and web application components. Although none of the CVEs are known to have been exploited in the wild and no public PoC exploit exists, CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts, indicating high global risk. Greenbone’s OPENVAS ENTERPRISE FEED provides remote banner version checks for the BT26-03 CVEs, helping defenders identify affected BeyondTrust RS and PRA appliances and prioritize remediation.

 

Contact Test Now Buy Here Back to Overview
15. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-15 10:59:032026-08-03 11:54:47BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access
Joseph Lee

CVE-2026-48282: CVSS 10 Flaw in Adobe ColdFusion Is Actively Exploited and More

Blog

CVE-2026-48282 (CVSS 10) is a critical path traversal vulnerability [CWE-22] in Adobe ColdFusion. According to Adobe’s Security Bulletin [APSB26-68], the issue affects ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Exploitation is network-based, which increases the risk to exposed ColdFusion instances, and exploitation does not require authentication. A successful attack allows arbitrary remote code execution (RCE) in the context of the current user.

KEVIntel captured honeypot attacks targeting CVE-2026-48282, indicating that active exploitation may be underway, and CISA has added the flaw to their Known Actively Exploited (KEV) list. Watchtowr Labs has published a public Proof-of-Concept (PoC) exploit with full technical root-cause analysis. Multiple national CERT alerts have been issued for CVE-2026-48282, indicating high concern globally [1][2][3][4][5][6][7][8].

CVE-2026-48282-adobe-coldfusion-exploited

In total, 11 CVEs were disclosed in Adobe’s APSB26-68 advisory, and six of those were assigned the highest possible CVSS severity rating. The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and all other CVEs disclosed in Adobe’s APSB26-68 advisory affecting Adobe ColdFusion. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Risk Assessment of CVE-2026-48282 in Adobe ColdFusion

CVSS 10 · CriticalActively exploitedIn CISA KEVPublic PoC

Adobe has assigned CVE-2026-48282 the highest CVSS severity rating. The primary defensive concern is that a path traversal [CWE-22] issue in a web-facing application server can allow an attacker to move outside intended directory boundaries and reach sensitive resources. Adobe reports that CVE-2026-48282 can lead to arbitrary RCE in the context of the current user. Because exploitation does not require privileges or user interaction, externally reachable instances carry the highest exposure.

Adobe ColdFusion is an enterprise application server used to build, deploy, and scale data-driven web applications, APIs, intranet portals, administrative systems, and cloud-connected business applications. The exploitation reporting should be treated as operationally significant even without additional technical detail.

Mitigating CVE-2026-48282 in Adobe ColdFusion

CVE-2026-48282 is remediated by updating to ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21. Adobe does not provide any alternative workarounds or compensating controls. Where instances are externally reachable, remediation should be prioritized. The OPENVAS ENTERPRISE FEED includes a remote_banner check to identify Adobe ColdFusion instances affected by CVE-2026-48282.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and every other CVE in Adobe’s APSB26-68 advisory. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Other CVEs From Adobe’s APSB26-68 Advisory

Adobe’s Security Bulletin [APSB26-68] covered a total of 11 CVEs. Six of these were assigned the highest CVSS criticality score. There are no reports of active exploitation for the CVEs described below, and no detailed technical analysis or PoC are available. All CVEs in the security bulletin affect the same product scope. Therefore, the mitigation described above covers all the vulnerabilities.

The ten additional CVEs disclosed in Adobe APSB26-68, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-48276 CVSS 10 · Critical EPSS 0.9% (56th)

An Unrestricted Upload of File with Dangerous Type vulnerability [CWE-434] allows arbitrary RCE in the context of the current user.

CVE-2026-48277 CVSS 10 · Critical EPSS 0.9% (54th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48281 CVSS 10 · Critical EPSS 0.9% (54th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48316 CVSS 10 · Critical EPSS 1.4% (69th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48283 CVSS 10 · Critical EPSS 0.6% (46th)

An Unrestricted Upload of File with Dangerous Type vulnerability [CWE-434] allows arbitrary RCE in the context of the current user.

CVE-2026-48313 CVSS 9.3 · Critical EPSS 1.6% (73rd)

A Path Traversal vulnerability [CWE-22] allows arbitrary file system read and limited write access. An attacker could access sensitive files and directories outside the intended access scope.

CVE-2026-48315 CVSS 9.3 · Critical EPSS 0.5% (42nd)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user. An attacker can inject malicious scripts into a web page, potentially gaining elevated access or control over the victim’s account or session. Exploitation requires the target to open a malicious file.

CVE-2026-48307 CVSS 8.8 · High EPSS 0.3% (23rd)

A reflected Cross-Site Scripting (XSS) vulnerability [CWE-79] allows an attacker to inject malicious scripts into a web page, potentially resulting in arbitrary code execution on the system of victims who open a malicious link.

CVE-2026-48285 CVSS 8.6 · High EPSS 0.4% (35th)

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] allows an attacker to bypass security measures and gain unauthorized read access.

CVE-2026-48314 CVSS 6.5 · Medium EPSS 0.3% (25th)

A Path Traversal vulnerability [CWE-22] allows an attacker to gain limited read and write access to unauthorized files or directories outside the intended restrictions.

Summary

Adobe’s Security Bulletin [APSB26-68] covered a total of 11 CVEs. Six of these were assigned the highest CVSS criticality score. In-the-wild exploitation has been reported for CVE-2026-48282, which potentially allows arbitrary RCE in the current user context. The affected scope is ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Adobe’s fixed versions are ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21.

The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and all other CVEs disclosed in Adobe’s APSB26-68 advisory affecting Adobe ColdFusion. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
13. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-13 14:55:492026-07-14 13:16:45CVE-2026-48282: CVSS 10 Flaw in Adobe ColdFusion Is Actively Exploited and More
Joseph Lee

June 2026 Threat Report: Technical Debt Demands Visibility

Blog

June 2026 Threat Report: technical debt demands visibility

The true impact that cyber security aware AI will have on the global threat landscape remains to be seen. By some reports, the CVE output for software made by major vendors is on the rise. This June 2026 threat report only scratches the surface of the major cyber security threats from this month. The month brought a concentrated wave of actively exploited enterprise vulnerabilities, with CISA logging multiple new additions to its Known Exploited Vulnerabilities (KEV) catalog throughout the month. At least one new critical perimeter network exploit was tied to an active ransomware affiliate.

Greenbone’s vulnerability coverage extends far beyond major, headline-grabbing IT security events, such as the ones in this monthly threat report, and keeps pace with the onslaught of AI driven disclosures. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Here are some of the top emerging threats to enterprise IT security from June 2026.

CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise Actively Exploited

CVSS 9.8 · CriticalActively exploitedIn CISA KEVPublic PoC

CVE-2026-20253 (CVSS 9.8, EPSS ≥ 95th pctl) allows an unauthenticated remote attacker to create or truncate arbitrary files in Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7. The flaw is due to missing authentication [CWE-306] on a PostgreSQL sidecar service endpoint. Splunk confirmed limited in-the-wild exploitation, and CISA has added the flaw to KEV. A full technical description with PoC exploit code has been published by WatchTowr demonstrating unauthenticated RCE. Shadowserver tracked more than 1,400 internet-exposed Splunk instances.

CVE-2026-20253 is patched in Splunk Enterprise 10.2.4 and 10.0.7, and customers should upgrade immediately. If patching is not possible, exploitation can be prevented by disabling the PostgreSQL sidecar service. However, disabling the service may disrupt Edge Processor, OpAmp, or SPL2 data pipelines. The OPENVAS ENTERPRISE FEED includes a remote analysis check and a separate remote banner check to identify affected instances.

CVE-2026-28318: SolarWinds Serv-U Exploited in DoS Attacks

CVSS 7.5 · HighActively exploitedIn CISA KEVPublic PoC

CVE-2026-28318 (CVSS 7.5, EPSS ≥ 60th pctl) allows an unauthenticated remote attacker to cause a denial of service (DoS) in SolarWinds Serv-U Managed File Transfer and FTP Server. CISA added the flaw to its KEV catalog; however, no campaign attribution has been made. A technical description has been published. Exploitation is achieved by simply including the Content-Encoding: deflate request header and can crash the Serv-U service. The flaw is caused by uncontrolled resource consumption [CWE-400] in crafted HTTP POST request handling.

There is significant risk of operational disruption to exposed file transfer servers used in regulated sectors such as healthcare, finance, and government. Exposed Serv-U instances were originally reported to be more than 12,000 by Shodan and roughly 3,000 by Shadowserver. However, Shodan detection had since fallen to less than 10,000 by the end of June.

SolarWinds advises customers to install Serv-U 15.5.4 Hotfix 1 immediately. If patching cannot be done right away, users can block POST requests containing the Content-Encoding: deflate header without losing any functionality. The OPENVAS ENTERPRISE FEED includes a remote banner check to detect vulnerable instances.

Living on the Edge: Emerging Threats to Perimeter Security

Vulnerabilities in network perimeter devices are particularly high risk because they are exposed to attack by arbitrary remote attackers. According to the latest Verizon DBIR 2026 report, exploiting publicly exposed software vulnerabilities is now the most common vector for initial access globally. Here are some of the most critical emerging threats to perimeter devices in June 2026.

CVE-2026-50751: Check Point Security Gateway Exploited in Ransomware Attacks

CVSS 9.3 · CriticalActively exploitedIn CISA KEVPublic PoCRansomware-linked

CVE-2026-50751 (CVSS 9.3, EPSS ≥ 98th pctl) and CVE-2026-50752 (CVSS 7.4, EPSS ≥ 90th pctl) affect Check Point VPN Remote Access, Mobile Access, Security Gateways, and Spark Firewalls. CVE-2026-50751 is being actively exploited with at least one post-compromise case linked to a Qilin ransomware affiliate. CISA has added CVE-2026-50751 to its KEV catalog. The first attacks were observed on May 7, 2026. A few dozen organizations have been targeted globally. PoC exploit code and a full technical description are publicly available for CVE-2026-50751. CVE-2026-50752 is not reported as actively exploited.

The CVEs are described below:

  • CVE-2026-50751 (CVSS 9.3, EPSS ≥ 98th pctl): Unauthenticated remote attackers can establish VPN access through a logic-flow and certificate-validation weakness in IKEv1 deployments.
  • CVE-2026-50752 (CVSS 7.4, EPSS ≥ 90th pctl): Could allow unauthenticated attackers to conduct adversary-in-the-middle attacks against VPN site-to-site connections.

Check Point has published recommendations for removing support for legacy protocols, upgrading affected instances to fixed versions, and provides additional security hardening advice [1][2]. The OPENVAS ENTERPRISE FEED includes remote banner detection for Gaia, Check Point’s unified security OS for Security Gateways, Security Management products, Software Blades, Check Point appliances, and Open Servers. Check Point Gaia version R80.20, R80.40, R81, R81.10, R81.20, R82, and R82.10 are affected.

Three CVSS 10 Flaws in Ubiquiti UniFi OS Allow Unauthenticated RCE

CVSS 10 · CriticalExploited as zero-dayIn CISA KEV

Three new CVSS 10 flaws affecting UniFi OS systems have been published and added to CISA’s KEV list. The flaws collectively allow attackers to modify underlying operating-system files and accounts, and execute commands. User reports indicate the flaws were likely exploited as zero-days to create rogue administrator accounts. Risk is elevated because UniFi OS devices centrally manage network infrastructure, making successful compromise a potential path for lateral movement into enterprise environments.

The CVEs are described below:

  • CVE-2026-34908 (CVSS 10): An attacker with network access can exploit an improper access control vulnerability [CWE-284] in UniFi OS devices to make unauthorized changes to the system.
  • CVE-2026-34909 (CVSS 10): An attacker with network access can exploit a path traversal vulnerability [CWE-22] in UniFi OS devices to access and manipulate files on the underlying system and access underlying accounts.
  • CVE-2026-34910 (CVSS 10): An attacker with network access can exploit an improper input validation vulnerability [CWE-20] in UniFi OS devices to execute command injection attacks.

Bishop Fox published a full technical analysis showing that CVE-2026-34908 and CVE-2026-34909 form an authentication gateway bypass caused by crafted NGINX request handling. Exploitation exposes internal routes and enables command injection via CVE-2026-34910.

Exploitation of all aforementioned CVEs has been validated against UniFi OS version 5.0.6. Ubiquiti fixed the vulnerabilities in UniFi OS Server version 5.0.8, released on May 21, 2026. No workarounds are available. The OPENVAS ENTERPRISE FEED includes a remote vulnerability check and remote banner check for Ubiquiti UniFi OS on various devices and an additional remote vulnerability check and remote banner check for Ubiquiti UniFi OS Server version 5.0.6 and prior.

Squidbleed (CVE-2026-47729) Memory Leak Has Public PoC

CVSS 6.5 · MediumPublic PoCNo ITW exploitation

CVE-2026-47729 (CVSS 6.5), also known as Squidbleed, allows an authorized Squid proxy user to leak another user’s cleartext HTTP request data. The flaw is caused by a heap over-read in the FTP directory-listing parser. Leaked data may include credentials, session tokens, API keys, and Authorization headers. Public proof-of-concept exploit code and a full technical description are available. However, in-the-wild exploitation has not been reported. Surprisingly, despite having a GitHub Security Advisory referencing the CVE by ID, CVE-2026-47729 has not been published to MITRE’s CVE.org or NIST NVD as of July 1st, 2026.

The flaw affects shared proxy environments where Squid can inspect cleartext HTTP or terminate TLS altogether, and all Squid versions dating back to a 1997 FTP parser change. Exploitation requires the Squid instance to be able to reach an attacker-controlled FTP server on TCP port 21. The flaw is fixed in the Squid 7.6 June 2026 release but can also be mitigated by disabling FTP support if not required. The OPENVAS ENTERPRISE FEED includes package-level detection for Linux distributions that have issued security advisories and a remote banner detection for affected versions of Squid proxy.

CVE-2026-10520 and CVE-2026-10523 in Ivanti Sentry

CVSS 10 · CriticalActively exploitedIn CISA KEVPublic PoC

CVE-2026-10520 (CVSS 10) and CVE-2026-10523 (CVSS 9.8) allow a remote, unauthenticated attacker to achieve root-level RCE and create arbitrary administrative accounts in Ivanti Sentry. CVE-2026-10520 has been added to CISA’s KEV catalog after reported exploitation attempts against honeypots. watchTowr published a full technical analysis including a public PoC exploit. Shadowserver reported large-scale exploitation of CVE-2026-10520, identifying 19 vulnerable instances in its scans with at least two identified as compromised.

  • CVE-2026-10520 (CVSS 10): An OS command injection vulnerability [CWE-78] allows a remote, unauthenticated user to achieve root-level remote code execution.
  • CVE-2026-10523 (CVSS 9.8): An authentication bypass vulnerability [CWE-288] allows a remote, unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.

Exploitation requires access to the management port 8443. Affected versions include Ivanti Sentry 10.5.1, 10.6.1, 10.7.0, and prior versions, with fixes available in 10.5.2, 10.6.2, and 10.7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes an active check and a remote banner check that cover both CVEs.

The HTTP/2 Bomb: DoS against All Major Web Servers

CVSS 7.5 · HighPublic PoCMulti-vendor DoS

HTTP/2 Bomb is a remote, unauthenticated denial-of-service (DoS) technique against HTTP/2 server implementations. The flaw affects the default HTTP/2 configurations in Apache HTTP Server, NGINX, Microsoft IIS, Envoy Proxy, and Cloudflare Pingora, among other digital products that package them. A detailed technical write-up is available, and Calif’s HTTP/2 Bomb companion repository lists self-contained per-server PoCs and Docker labs for major affected web servers, increasing the risk. HTTP/3 is not reported as directly vulnerable to the current HTTP/2 Bomb technique.

The exploit uses legitimate HTTP/2 features in a way the HPACK header compression spec did not constrain. Affected web servers failed to enforce the extra limits needed to make those features safe. Exploitation has a reported memory amplification of between 70:1 and 5.7K:1 and allows consuming 32 GB to 64 GB of server memory within seconds. The root cause is flawed HTTP/2 request handling, where HPACK-driven cookie expansion triggers excessive memory allocation and data amplification. Calif.io also states that the deeper root cause is a protocol specification issue. The major products related to HTTP/2 Bomb are described below:

  • CVE-2026-49975 (CVSS 7.5) — Apache HTTP Server mod_http2: Apache HTTP Server versions 2.4.17 through 2.4.67 are affected and the issue is fixed in Apache HTTP Server version 2.4.68.
  • CVE-2026-47774 (CVSS 7.5) — Envoy Proxy: Envoy versions before 1.35.11, 1.36.7, 1.37.3, and 1.38.1 are affected.
  • CVE-2026-49160 (CVSS 7.5) — Microsoft HTTP.sys / IIS: Affects Microsoft HTTP.sys, the Windows HTTP stack used by IIS and other Windows HTTP services. Microsoft addressed the issue in its June 9th, 2026 security updates.
  • No CVE assigned — nginx: All nginx versions before 1.29.8 are affected and the issue is fixed in nginx 1.29.8. Red Hat states that upstream nginx did not assign a CVE for HTTP/2 Bomb.

Quang Luong of Calif.IO attributes the discovery of HTTP/2 Bomb to OpenAI Codex. Many additional CVEs are expected to emerge as hardware and software vendors patch their products. Greenbone includes numerous vulnerability tests to detect HTTP/2 Bomb across a wide range of Linux distributions and other affected products. This includes detection for affected Apache HTTP Server products (CVE-2026-49975), Envoy Proxy (CVE-2026-47774), Microsoft IIS (CVE-2026-49160), and nginx despite the lack of CVE coverage.

Multiple Critical Flaws in SAP SE and SAP NetWeaver AS ABAP, and ABAP Platform

CVSS 9.9 · CriticalNo known exploitationPatch available

Three new critical flaws affecting SAP products have been published. Collectively, the flaws impact NetWeaver AS ABAP and ABAP Platform, SAP NetWeaver Application Server Java Web Container, SAP Commerce Cloud, and SAP Data Hub. Risk is elevated because the flaws can allow unauthorized access, sensitive data exposure, file modification, application crashes, memory corruption, arbitrary code execution, and connection hijacking without user interaction in several cases. No active exploitation has been observed in the wild. Public PoC exploits or a full public exploit chain are not available. Mitigate by applying SAP’s June 2026 Security Patch Day updates immediately.

Details on the three CVEs are included below:

  • CVE-2026-44748 (CVSS 9.9): An authenticated attacker with normal privileges can obtain a valid signed message and send modified signed XML documents to the verifier. This can result in acceptance of tampered identity information, leading to unauthorized access to sensitive user data and disruption of normal system usage. SAP NetWeaver AS ABAP version 7.02, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54, 7.55, 7.56, 7.57, 7.58, 8.16, 9.18, and 9.19 are affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.
  • CVE-2026-27671 (CVSS 9.8): Due to improper RFC protocol validation in the SAP Kernel, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. SAP NetWeaver AS ABAP version 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, and 9.19 are affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.
  • CVE-2026-40128 (CVSS 9.0): An unauthenticated attacker can craft a malicious HTTP logon request that manipulates file inclusion parameters. Exploitation enables path traversal and processing of the included file and allows the attacker to view or modify sensitive information or render any part of the local system unavailable. SAP NetWeaver AS Java version 7.50 is affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.

Summary

June 2026 underscored accelerating enterprise risk from actively exploited flaws in Splunk, SolarWinds Serv-U, Check Point gateways, Ubiquiti UniFi OS, Ivanti Sentry, Squid, HTTP/2 implementations, and SAP platforms. Public PoCs, KEV listings, ransomware links, and exposed internet-facing assets reinforce the need for rapid patching, compensating controls, and continuous vulnerability detection across perimeter and core infrastructure.

Greenbone’s OPENVAS BASIC is available free of charge and includes a two-week trial of the OPENVAS ENTERPRISE FEED — giving your security team immediate access to automated vulnerability detection for the CVEs covered in this report and tens of thousands more. Start your free trial today.

 

Contact Test Now Buy Here Back to Overview
9. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-09 15:05:342026-07-09 15:24:53June 2026 Threat Report: Technical Debt Demands Visibility
Greenbone AG

Sovereignty was a promise. Now it’s becoming a test criterion.

Blog

EU as a symbol of digital sovereignty – Greenbone explains the CADA sovereignty levels

On June 3, 2026, the European Commission proposed the Cloud and AI Development Act (CADA)—the centerpiece of its new Tech Sovereignty Package. At its core: a four-tier model that public contracting authorities will use in the future to assess how sovereign a cloud provider truly is—not just where the data is located, but who owns the provider, who controls it, and which legal system it is subject to.

CADA is still a proposal, not yet law, but the direction is remarkably clear. Commission Vice President Henna Virkkunen has stated publicly that providers subject to the U.S. CLOUD Act will face structural difficulties in reaching the top two levels—regardless of where their data centers are located in Europe. The CLOUD Act allows U.S. authorities to access data from U.S. companies, no matter where in the world that data is located. Anyone subject to this law can hardly credibly promise “no influence by a third country.” That is precisely the test for Level 4.

The four levels, briefly explained

An overview of the four CADA sovereignty levels

L1

EU Location

Data and infrastructure are located in the EU. No additional requirements regarding ownership, personnel, or the software supply chain.

✓ Available to U.S. hyperscalers with an EU region

L2

Independence & Transparency

Additionally: verifiable independence from third countries and transparency throughout the entire software supply chain.

⚠ Depends on ownership structure and transparency requirements

L3

EU Ownership & EU Control

The provider must be based in the EU, EU-owned, and under EU control—including requirements regarding the citizenship of its staff.

✗ Structurally unfeasible under the U.S. CLOUD Act

L4

Complete digital sovereignty

Full transparency and control over the entire software supply chain, with no influence from third countries. The highest degree of digital independence recognized by the regulatory framework.

✗ Structurally unachievable under the U.S. CLOUD Act

Why this doesn’t end with cloud infrastructure

CADA is explicitly written for the public procurement of cloud services. But the underlying question is not specific to the cloud. It is: Who controls the software running in critical infrastructure—and to which legal system is that party accountable?

This question applies with equal validity to every security-critical software component. And hardly any component sits deeper at the heart of IT security architecture than the vulnerability management system, which knows where every vulnerability in a country’s infrastructure lies.

Who supplies this software, who controls it, and who—in case of doubt—could be forced to grant access or remain silent—this is no longer an academic question. It is the very question that CADA is now making binding for cloud providers.

Applying this standard: Where does Greenbone stand?

We are not a cloud provider as defined by CADA and will therefore not be “CADA-certified.” But if you apply the same criteria to an IT security system, a clear picture emerges:

  • Control & Legal System: Greenbone is a company founded in Germany and firmly rooted in Europe. We are subject to German and European law, not the U.S. CLOUD Act.
  • Staff: Our development and operations team is based in Germany and the EU.
  • Software Supply Chain: OPENVAS is open source. Not “auditable upon request”—but fully transparent to everyone, at any time. This is a stronger position than “auditable software,” as required by CADA for Levels 2/3.
  • Disclosure Requirements: Because we are not subject to U.S. law, there is no legal framework through which we could be forced into tacit cooperation with third-country authorities—the kind of “hidden disclosure” that CADA aims to protect against.

Many established companies are based in the U.S. This structural reality is what makes CADA measurable for the first time. An EU data center region does not change this as long as the parent company is subject to the CLOUD Act.

What this means for you

CADA is not yet in effect. But for the first time, the Commission has precisely defined what “digital sovereignty” actually means—in four verifiable stages rather than in marketing jargon. For government agencies, KRITIS operators, and public contracting authorities, this will likely become a requirement in their specifications.

Those who are already built on this foundation today won’t have to migrate tomorrow.

 

Contact Try for Free Buy Here Back to Overview
8. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-08 11:28:562026-07-08 11:28:56Sovereignty was a promise. Now it’s becoming a test criterion.
Greenbone AG

The Missing Handoff: How KIX and Greenbone Turn Vulnerability Scans Into Action

Blog

Greenbone, home of OPENVAS, and KIX Service Software

For the first time, attackers are exploiting unpatched vulnerabilities more often than they’re stealing credentials. According to Verizon’s 2026 Data Breach Investigations Report, vulnerability exploitation now accounts for 31% of breaches, ahead of credential theft at 13%. And the gap is moving in the wrong direction for defenders: the median time to fully patch a vulnerability climbed to 43 days, up from 32 the year before, while organizations patched only 26% of the vulnerabilities on CISA’s Known Exploited Vulnerabilities list, down from 38% in 2024 (we broke down what’s driving this shift here).

Scanners aren’t the bottleneck here. Finding a vulnerability and actually fixing it have turned into two separate problems, and the second one is losing ground.

Two trend charts: median time to fully patch a vulnerability rose from 32 days in 2025 to 43 days in 2026, while the share of known exploited vulnerabilities actually patched fell from 38 percent in 2024 to 26 percent in 2026.

Median time to fully patch a vulnerability
2025
 
32 days
2026
 
43 days
+11 days, 34% slower
Known exploited vulnerabilities actually patched
2024
 
38%
2026
 
26%
−12 points
Source: Verizon 2026 Data Breach Investigations Report

Detection was never the hard part

Greenbone’s OPENVAS has spent nearly two decades getting good at the first half: scanning a network, identifying what’s exposed, and scoring how dangerous it is. Elmar Geese, Greenbone’s CEO, likes to compare it to a swarm of robots checking every door and window in a house. They’re fast and thorough, and when they find a broken lock, they sound the alarm.

But an alarm only matters if someone acts on it. In most organizations, that’s where things stall. A scan result lands in a report, or an inbox, or a spreadsheet nobody opens until the next audit. Someone has to read it, work out what it actually means for their specific systems, decide who owns the fix, and turn that into a tracked piece of work with a deadline. That step requires security expertise that not every IT team has sitting around, and it’s exactly where things get lost: severity gets misjudged, tickets get duplicated or never created, ownership gets argued over after the fact instead of decided up front.

This is the part of vulnerability management that doesn’t show up in scanner marketing, but it’s where most of the real delay lives.

What the integration actually changes

KIX CEO Rico Barth puts it simply: the partnership closes the gap “between the detection and the resolution of vulnerabilities.” That gap is where a security finding used to need a translator. Now it doesn’t.

KIX, the open-source ITSM platform, and Greenbone have built a direct line between the two halves of the problem. When OPENVAS flags a vulnerability, it doesn’t generate a report and stop there. It opens a ticket in KIX automatically: classified as a security incident, tied to the specific device or software it affects, and sent to the team that owns that asset. The fix-it workflow, with deadlines, reminders, and escalations, starts the moment the vulnerability is confirmed, not whenever someone gets around to reading the scan output.

It also means an IT admin opening a ticket isn’t starting from zero. The asset, the affected system, who needs to be told, and how this fits into everything else currently open are all sitting right there. Nobody has to cross-reference three different tools to figure out what’s actually going on.

Flow diagram showing urgency decreasing as a vulnerability moves from detection, in red, to an automatically created ticket, in amber, to tracked resolution, in green.

Vulnerability detected
Flagged the moment a scan completes
 
 
 
Ticket auto-created
Classified and linked to the asset
 
 
 
Tracked to resolution
Deadlines, reminders, and escalation

The bonus nobody asked for: finding the stuff you didn’t know you had

There’s a side effect that turns out to matter almost as much as the ticketing itself. OPENVAS scans more than the systems IT already knows about. It finds the laptop a department bought without asking IT, or the server someone spun up two years ago and forgot about. That inventory now flows straight into KIX’s asset database.

Shadow IT is usually framed as a policy problem. In practice, it’s a visibility problem that gets worse as networks grow. Greenbone customers are routinely surprised by what shows up the first time their environment gets properly scanned. Folding that discovery into the same system that already handles tickets and ownership means an unknown device gets absorbed into the normal IT process right away, instead of sitting in its own blind spot.

Why this matters more given who’s actually doing the work

IT and security teams are stretched thin almost everywhere, and the manual interpretation step in vulnerability management has always assumed there’s enough specialized staff to do it well. That assumption is getting shakier every year. Take away the step where a human has to manually triage, classify, and route every finding, and smaller or generalist IT teams no longer need to borrow security expertise they didn’t have in-house just to keep up.

It also helps with something that eats more time than it should: proving you did the work. Documentation, deadlines, and resolution history land automatically in KIX, which makes audits against frameworks like NIS-2, ISO 27001, or BSI-Grundschutz considerably less painful, since the evidence trail already exists instead of getting reconstructed after the fact.

Try it where it counts

If your team is running OPENVAS and KIX separately today, or evaluating either one, this integration is worth a closer look specifically because it removes a step rather than adding one. Get in touch with us to see how the handoff from scan to fix works in your own environment, and what it would take to set up. And if you’re not scanning with OPENVAS yet, OPENVAS BASIC is a reasonable place to start before connecting the rest.

KIX Service Software logoAbout KIX Service Software

KIX develops and markets the IT service management software of the same name, one of the leading open-source ITSM systems on the market. Founded in 2006, the company employs more than 50 people across Germany and serves over 400 customers across industries for IT service management and technical support. More at kixdesk.com.

Greenbone logoAbout Greenbone

Greenbone develops OPENVAS, the most widely used open-source solution for vulnerability management, with more than 100,000 installations worldwide. Founded in 2008 and based in Osnabrück, Greenbone focuses on proactive IT security and data sovereignty through fully on-premises deployment. Greenbone is certified to ISO 9001, ISO 27001, and ISO 14001. More at greenbone.net.

 

Contact Test Now Buy Here Back to Overview
7. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-07 08:38:382026-07-07 10:38:33The Missing Handoff: How KIX and Greenbone Turn Vulnerability Scans Into Action
Joseph Lee

Cisco Enterprise Devices: More Critical Flaws and Active Exploitation in June 2026

Blog

Cisco products have been battered in 2026 by critical-severity, actively exploited vulnerabilities in recent months [1][2][3][4][5][6][7][8][9]. Recently exploited Catalyst SD-WAN Manager and Controller flaws include CVE-2026-20133 (CVSS 7.5, EPSS >= 95th pctl), CVE-2026-20128 (CVSS 7.8, EPSS >= 90th pctl), CVE-2026-20122 (CVSS 5.4, EPSS >= 93rd pctl), CVE-2026-20127 (CVSS 10, EPSS 99th pctl), and CVE-2026-20182 (CVSS 10, EPSS >= 99th pctl). In total, eleven Cisco vulnerabilities have appeared in CISA’s Known Exploited Vulnerabilities (KEV) catalog this year.

SD-WAN platforms are attractive to cyber adversaries because they centralize routing, policy enforcement, network visibility, and administrative control across enterprise IT environments. Repeated exploitation of SD-WAN flaws indicates that attackers are prioritizing network infrastructure targets that can support traffic manipulation [T1565.002], lateral movement [TA0008], persistence [TA0003], and broader operational impact including ransomware attacks.

Greenbone’s OPENVAS ENTERPRISE FEED has detection for all CVEs discussed in this blog post and includes a dedicated family for detecting Cisco security vulnerabilities. Here are the top new emerging threats affecting Cisco products from June 2026:

More critical Cisco flaws and active exploitation in June 2026

More critical Cisco flaws
and active exploitation

CVE-2026-20245 and CVE-2026-20262: New Flaws in Catalyst SD-WAN Actively Exploited

CVE-2026-20245: Authenticated Command Execution with Root-Level Privileges

CVE-2026-20245 (CVSS 7.8, EPSS >= 57th pctl), published on June 4, 2026, allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as root on Cisco Catalyst SD-WAN Controller, Manager, and Validator. The root cause is insufficient validation of user-supplied input in uploaded files [CWE-20]. According to Mandiant, attackers used stolen credentials in tandem with CVE-2026-20245 to gain root-level access via a malicious CSV upload.

CVE-2026-20245 affects Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, and Cisco Catalyst SD-WAN Validator across all deployment types, including on-premises, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government. Cisco has released fixes in Catalyst SD-WAN releases 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. There are no workarounds, and Cisco recommends upgrading to a fixed release after preserving logs and collecting admin-tech files for compromise review.

CVE-2026-20262: Authenticated File Creation with Attack Chain for Root-Level Compromise

CVE-2026-20262 (CVSS 6.5, EPSS >= 63rd pctl), published on June 15, 2026, allows an authenticated remote attacker with valid low-privileged write access to create or overwrite files on Cisco Catalyst SD-WAN Manager systems. The flaw is caused by improper pathname restriction during file upload [CWE-22]. Cisco confirmed limited exploitation activity in June 2026, and CISA has added CVE-2026-20262 to its KEV catalog. There is no indication of a public PoC exploit or detailed third-party technical analysis.

According to Cisco, attackers can obtain the required privileges through valid credentials or prior exploitation of CVE-2026-20182 (CVSS 10) or CVE-2026-20127 (CVSS 10), and the vendor’s official advisory describes limited cases where exploitation pushed configuration changes to edge devices. Internet-exposed Catalyst SD-WAN Manager systems are at higher risk because exploitation can upload suspicious WAR or JSP files, deploy malicious code, and potentially support follow-on activity that leads to root-level compromise.

Cisco Catalyst SD-WAN Manager was affected regardless of device configuration across on-premises, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP) deployments. Cisco fixed the issue in Catalyst SD-WAN Manager releases 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. There are no workarounds for CVE-2026-20262, so mitigation requires upgrading to a fixed release. The OPENVAS ENTERPRISE FEED includes a remote banner check for identifying devices affected by CVE-2026-20262.

CVE-2026-20230: Unified Communications Manager Actively Exploited via Unauthenticated HTTP Requests

CVE-2026-20230 (CVSS 8.6, EPSS 42nd pctl), published on June 3, 2026, allows an unauthenticated remote attacker to exploit Cisco Unified Communications Manager and Unified CM Session Management Edition through a WebDialer server-side request forgery flaw [CWE-918]. The root cause is improper input validation of HTTP requests. Exploitation requires WebDialer to be enabled, which is disabled by default. However, successful attacks can write files to the underlying OS and support later privilege escalation to root-level.

CISA has added CVE-2026-20230 to its KEV list, making it the second known actively exploited CVE in Cisco Unified Communications Manager in 2026. Reports indicate the vulnerability is being used to drop web shells [T1505.003] for remote code execution (RCE). Public PoC exploit code and a full technical description have been released by SSD Secure Disclosure.

Cisco released fixes for Unified CM and Unified CM SME 14SU6 and 15SU5 or COP1, noted there are no workarounds, and recommends disabling WebDialer as a temporary mitigation until patching is complete. The OPENVAS ENTERPRISE FEED includes package-level detection for CVE-2026-20230.

Two Critical Flaws in Cisco ISE — One Allows Root-Level RCE

CVE-2026-20181 (CVSS 9.1, EPSS 43rd pctl) and CVE-2026-20190 (CVSS 7.5, EPSS 29th pctl), published on June 17, 2026, allow RCE, privilege escalation, denial of service (DoS), and information disclosure in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. Active exploitation has not been reported and PoC exploit code or detailed technical analysis are not yet available.

CVE-2026-20181 allows an authenticated administrator to exploit HTTP requests to gain user-level OS access and escalate to root-level privileges. CVE-2026-20190 allows an unauthenticated attacker to access sensitive information, including hashed credentials that could support follow-on attacks if those credentials can be cracked. Both flaws affect Cisco ISE and ISE-PIC regardless of device configuration. In single-node deployments, CVE-2026-20181 can make the ISE node unavailable, preventing authentication by other endpoints until the node is restored.

Cisco states that there are no workarounds for either vulnerability, so affected customers should upgrade or apply the available hot patch where applicable. See Cisco’s advisory for specific affected versions and upgrade instructions. The OPENVAS ENTERPRISE FEED includes package-level detection for both CVE-2026-20181 and CVE-2026-20190 [1][2].

Summary

Cisco faced another wave of enterprise security threats to its products in June 2026 amid an ongoing barrage. Emerging threats include new actively exploited Catalyst SD-WAN and Unified Communications Manager vulnerabilities, plus critical Cisco ISE flaws. The issues enable root-level command execution, file creation, SSRF attacks, credential exposure, and DoS, as well as potential follow-on attacks if credentials are cracked. Greenbone’s OPENVAS ENTERPRISE FEED has detection for all CVEs discussed in this blog post and includes a dedicated family for detecting Cisco security vulnerabilities. Defenders can try Greenbone’s flagship OPENVAS BASIC for free, including a two-week trial of the OPENVAS ENTERPRISE FEED.

Contact Test Now Buy Here Back to Overview
1. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-01 13:09:312026-07-01 13:09:31Cisco Enterprise Devices: More Critical Flaws and Active Exploitation in June 2026
Greenbone AG

The 5 Stages of Vulnerability Management Maturity

Blog

Effective vulnerability management does not begin and end with scanning. To be effective, vulnerability management requires a solid understanding of both scanner technology and your IT infrastructure. Operationally, vulnerability management depends on having reliable and repeatable processes, well-defined ownership, integration with day-to-day IT operations, and strategic governance.

Every organization exists at a different stage of VM maturity. Some are just beginning to introduce vulnerability scanning. Others have established operational processes but lack structured prioritization, remediation tracking, or business alignment. The most mature organizations treat vulnerability management as an essential security control for mitigating exposure to emerging threats and reducing overall business risk.

A vulnerability management maturity model provides a structured way to assess the current state of your organization’s program. It helps security, IT, and business stakeholders understand where their security posture stands today, identifies “blockers” limiting progress, and defines next steps toward a more effective and sustainable vulnerability management process.

In this article, we will review a structured model for defining VM maturity. The model defines 5 levels of maturity and explains how to identify where your organization sits within the model. It also describes the limitations that each level imposes on resilient operational cyber security.

Also interesting: Key Performance Indicators (KPI) for Measuring Vulnerability Management Performance

Understanding the 5 Stages of Vulnerability Management Maturity

Vulnerability management maturity can be divided into five levels. Each level reflects a different stage of discipline, operational capability, organizational involvement, and governance maturity. Organizations typically progress from basic technical scanning toward a risk-driven security program that is integrated into IT operations and continuously improved based on measurable KPI outcomes.

  1. Ad-hoc
  2. Repeatable / Operational
  3. Defined / Managed
  4. Integrated / Controlled
  5. Optimized / Strategic

Stage 1 – Ad-hoc

At the Ad-hoc stage, vulnerability management is typically a brand new activity to an organization, or being performed inconsistently. Scanning is not formally scheduled, and there are no documented security processes. The organization may have a scanning tool installed, but scan coverage is unmeasured and results are not systematically used to drive remediation.

The informal mindset at this stage is often: “We’ll scan it somehow.” While this attitude and raw effort may provide some initial visibility, it does not constitute a reliable vulnerability management program.

The Limitations of an Ad-hoc / Initial Security Program

The main limitation at this stage is the absence of structure. Without a complete asset inventory, an organization doesn’t know if critical systems are being scanned. Without a defined scope or schedule, scanning activity remains an afterthought. Without clear ownership, discovered vulnerabilities may not be communicated to the correct teams for remediation.

Common limitations include:

  • No complete asset inventory
  • No defined scan scope or schedule
  • No ownership or responsibilities
  • No reporting or KPIs
  • No structured remediation process

Stage 2 – Repeatable / Operational

At the Repeatable / Operational stage, vulnerability scanning is more consistent. Regular scans are performed, basic operational stability exists, and the organization has initial visibility into vulnerabilities across part of its environment. This level represents an important transition from informal activity to repeatable execution. An organization now reliably performs scans on a recurring basis, and some responsibilities for the vulnerability management program have been assigned, such as administrator or technical owner.

An organization may be scanning systems regularly, but it has not yet established a fully managed process for auditing, prioritizing, tracking, and remediating vulnerabilities.

The Limitations of a Repeatable / Operational Security Program

This Repeatable / Operational stage is still primarily technical. The main limitation at this stage is that vulnerability data is not yet effectively managed through a structured lifecycle. Organizations know where vulnerabilities exist, but lack a formal process for deciding which issues matter most, who should fix them, and by when. Governance is limited to basic reporting, without KPI-driven management or formal performance targets.

Common limitations include:

  • No structured prioritization
  • No defined remediation SLAs
  • Limited tracking of remediation
  • Weak cross-team collaboration

Stage 3 – Defined / Managed

At the Defined / Managed stage, vulnerability management becomes structured and measurable. An organization has established processes for identifying, prioritizing, remediating, and tracking vulnerabilities. Responsibilities are clearly assigned across relevant stakeholders, including IT and security teams. This level marks the point where vulnerability management becomes a managed operational process rather than a scanning activity.

An organization at this stage uses KPIs to measure performance, applies risk-based prioritization, and follows well-defined remediation workflows. Scan coverage is verified, and authenticated scanning is in place for defense in depth.

A Level 3 program can answer important management questions: Which vulnerabilities are most important? Who owns remediation? How long does remediation take? Are teams meeting defined targets? Where are recurring issues appearing?

The Limitations of a Defined / Managed Security Program

A program at this level is structured but not automated or deeply integrated. Processes are documented and measurable, but execution still depends largely on manual coordination. Integration of scanning infrastructure with IT operations, ticketing, patch management, or change management is non-existent or incomplete.

Common limitations include:

  • Limited automation
  • Weak integration into IT processes
  • Limited business alignment

Stage 4 – Integrated / Controlled

At the Integrated / Controlled stage, vulnerability management is firmly integrated into IT operations. The program is no longer managed as a separate security activity; it is integrated into the operational systems and workflows that control infrastructure, applications, patching, change management, incident response, and service management.

Processes at this stage are automated and scalable. Vulnerability findings can be converted into tickets, assigned to the correct owners, tracked through remediation, and measured against defined targets. Integrations with ITSM, SIEM, patch management, and related operational systems enable end-to-end visibility and control. Overall, an organization can manage vulnerability remediation with more consistency, accountability, and operational efficiency.

The Limitations of an Integrated / Controlled Security Program

The main limitation at this stage is a lack of strategic optimization. An organization has strong processes and integrations, but isn’t using vulnerability management data for feedback into long-term strategic planning, investment planning, or continuous optimization.

Common limitations include:

  • Limited strategic steering
  • Optimization potential not fully leveraged

Stage 5 – Optimized / Strategic

At the Optimized / Strategic stage, vulnerability management is risk-driven, continuously improving, and strategically aligned with business objectives. An organization not only treats vulnerabilities as technical defects; it evaluates them in the context of business risk, asset criticality, threat exposure, operational impact, and security strategy.

Continuous improvement is embedded into programs at this level. Metrics, remediation data, recurring vulnerability patterns, exception handling, and risk decisions are used to refine the vulnerability management process over time. Vulnerability management becomes part of a broader security governance and risk management capability.

The Limitations of an Optimized / Strategic Security Program

There are typically no major structural gaps at this maturity level. The program is stable, integrated, governed, and strategically aligned. Remaining limitations are considered optimization opportunities rather than foundational weaknesses.

Common optimization areas may include:

  • Refining risk models
  • Improving automation accuracy
  • Enhancing business context
  • Reducing remediation friction
  • Improving predictive and trend-based analysis

Summary

Vulnerability management maturity is about much more than whether an organization owns a scanning tool and how often scans are conducted. As organizations progress from Ad-hoc maturity to an Optimized / Strategic vulnerability management program, the process evolves from a technical one into a strategic security capability.

At its core, VM maturity is defined by how consistently an organization can identify vulnerabilities, prioritize them based on risk, assign ownership, track remediation, measure performance, and improve the process over time. An immature program provides occasional visibility, but cannot reliably guarantee that risk is reduced to an acceptable level. A highly mature program connects technology, process, organization, and governance into a controlled lifecycle.

Once an organization understands its existing maturity level, it can plan practical next steps. Asset coverage will improve, standards and process will be well understood by stakeholders, and well-defined ownership and SLAs will ensure reliable and effective results. The overall result is a strategic reduction in business risk.

Contact Test Now Buy Here Back to Overview
26. June 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-06-26 09:33:262026-06-29 10:09:57The 5 Stages of Vulnerability Management Maturity
Greenbone AG

Cyber Resilience Act and Open Source Software: What Software Vendors and Stewards Need to Know

Blog

Update — 27 July 2026

The European Commission has approved its guidance on applying the CRA to open-source software (Communication C(2026) 5252 and Annex), finalizing what was still a draft when this post first went live. We’ve updated the post to match: the “commercial activity” test now turns on whether access to the software itself, including its maintenance, is gated behind payment, not simply whether paid services are sold alongside it. The guidance also sets out what qualifies as FOSS in the first place, and confirms the reporting timeline and scope that apply to open-source software stewards under Article 24(3).

The CRA’s scope for open-source software (OSS) was one of the most contested parts of the regulation. The OSS community raised legitimate concerns during the legislative process such as how should manufacturer obligations apply to non-commercial, volunteer-driven projects? The final regulation offers an answer, though how convincing that answer is depends on who you ask. The European Commission (EC) has been clarifying the details through guidance since March 2026, and approved the content of that guidance on 27 July 2026.

For companies like Greenbone that both steward an open-source project (OPENVAS) and sell commercial products built on it, the answer is clear: full manufacturer obligations apply to the commercial side, and steward obligations apply to the open-source community activities. Knowing where those lines fall is important.

Open Source & CRA

Open Source & CRA

The CRA’s Three-Tier Approach to Open-Source Software

Tier 1: Non-Commercial Open-Source Projects and Their Contributors (Out of Scope)

Free and open-source software (FOSS) developed and distributed in a purely non-commercial context (i.e. volunteers building software and sharing it freely, with no commercial intent or support model) does not impose CRA obligations on its creator or distributor. Only FOSS supplied in the course of a commercial activity falls in scope, and the EC’s guidance confirms that merely supplying non-monetized FOSS is not a commercial activity.

That said, “non-commercial” is still perhaps more narrowly defined than many projects assume. Accepting donations does not automatically make a project commercial. However, (EU) 2024/2847 Recital 15 states that “accepting donations exceeding the costs associated with the design, development and provision” does constitute commercial activity. The EC’s CRA guidance and (EU) 2024/2847 Recital 18 also state that the CRA does not apply to individuals or companies that merely contribute source code to FOSS projects that are not under their responsibility.

Tier 2: Open-Source Software Stewards (Lighter Obligations)

The CRA introduces the legal definition of an “open-source software steward”: a legal person that provides sustained, systematic support for the development of open-source products intended for commercial activities, or ensures those products’ viability. This covers software foundations, industry consortia, and companies that maintain and support OSS projects used commercially by others. A natural person is not classified as an OSS steward under (EU) 2024/2847 Article 3(14).

Stewards do not face the full obligations that manufacturers do. Their obligations are lighter than full manufacturer requirements: no CE marking, no formal conformity assessment, no required retention of technical documentation. However, under (EU) 2024/2847 Article 24, open-source software stewards must still:

  • Maintain a cyber security policy that fosters secure development of the OSS products they support
  • Cooperate with market surveillance authorities and make security documentation available on request
  • From 11 September 2026, report actively exploited vulnerabilities under the same 24-hour early-warning, 72-hour notification, and 14-day final-report timeline that applies to manufacturers, to the extent the steward is involved in developing the product (Article 24(3))
  • Report severe security incidents, but only those affecting the network and information systems that the steward itself provides for the product’s development (Article 24(3))
  • Effectively remediate vulnerabilities and ensure they are accessible to users without undue delay
  • Establish a policy that fosters voluntary vulnerability reporting by the developers of the software product

Stewards are also exempt from administrative fines for CRA infringements under Article 64(10). Enforcement works through cooperation and corrective measures rather than financial penalties.

Tier 3: Commercial OSS Vendors (Full Manufacturer Obligations)

If an individual (natural person) or legal person (such as a company or other type of organization) develops and distributes OSS and places it on the EU market in the course of commercial activity, they qualify as a manufacturer under the CRA. The CRA’s threshold for “commercial activity” is broad, but the guidance clarifies the decisive factor: whether access to the software itself, including its maintenance, is conditioned on payment — not simply whether professional services are sold alongside it. SLA-backed hosting or a paid edition that gates access to the software constitutes commercial activity; offering optional paid support around software that otherwise remains freely available typically does not. All Annex I requirements apply to manufacturers: secure-by-default design, vulnerability handling, 24-hour incident reporting, SBOM, technical documentation, and CE marking.

Manufacturers remain responsible for vulnerability handling in their own products, including vulnerabilities caused by integrated third-party OSS components. (EU) 2024/2847, Article 13 specifies that manufacturers must exercise due diligence when integrating third-party components. Upon identifying a vulnerability in an integrated component, including an FOSS/OSS component, they must report the vulnerability to the person or entity manufacturing or maintaining that component and, without delay, remediate the vulnerability in accordance with (EU) 2024/2847 Annex I, Part II.

The Cyber Resilience Act requires regular vulnerability assessments and external audits – on a continuous and sustainable basis.

OPENVAS SECURITY INTELLIGENCE supports your CRA compliance – on premises or in the cloud. Contact us to learn more.

➜ Achieve CRA compliance together

The EC’s CRA Guidance: What We Know Now

A public consultation on the EC’s draft guidance ran from 3 March to 13 April 2026. On 27 July 2026, the European Commission approved the content of its guidance on applying the CRA (Communication C(2026) 5252 and its Annex). The guidance is non-binding and will formally apply once all EU-language versions have been adopted; some edge cases remain open to interpretation, but this is no longer a draft. In its guidance, the EC clarifies the definition of “commercial activity” and addresses other key issues regarding scope, including what qualifies as FOSS.

Key clarifications include:

  • A product can be free and open-source and still be considered “made available on the market” if it is also offered as part of a commercial service or monetized support model
  • The presence of publicly available code alone, such as a GitHub repository, does not constitute market placement; a commercial relationship is what imposes responsibility
  • Dual-license models (free OSS edition + commercial enterprise edition) place the commercial edition firmly within scope of the CRA; the free edition’s status further depends on its association with commercial activity
  • Responsibility follows governance: whoever publishes and effectively controls a project bears the obligations, not whoever technically publishes changes to the software’s source code
  • Manufacturer responsibility also extends beyond the original developer to companies integrating or rebranding OSS components into products placed on the EU market
  • To qualify as FOSS in the first place, software must meet two cumulative conditions: a licence granting the full set of rights to access, use, modify, and redistribute it, and source code that is genuinely openly shared — not limited to paying customers or a restricted group

September Reporting: The Clock Is Ticking

The first hard CRA deadline applies to all products with digital elements, including OSS. From 11 September 2026, manufacturers and stewards must report actively exploited vulnerabilities and severe incidents that may affect the security of the digital products they are responsible for.

The reporting deadlines are tight: an early warning is due within 24 hours of awareness, a full notification within 72 hours, and a final report within 14 days for exploited vulnerabilities or one month for severe incidents. Reports are submitted through ENISA’s Single Reporting Platform (SRP); onboarding and registration guidance has been rolling out from ENISA since 31 July 2026, with the platform itself scheduled to go live by 11 September 2026.

What This Means for Greenbone

Greenbone operates across two tiers: as a manufacturer of digital products, and as an open-source software steward. As discussed above, the CRA imposes distinct obligations for both of these roles. As a manufacturer, Greenbone is responsible for the commercialized OPENVAS enterprise IT security products, and, as a steward, we take responsibility for our FOSS community projects.

Greenbone meets our manufacturer responsibilities through a wide range of IT security policies, controls, and response plans. This includes continuous vulnerability management, GDPR-compliant architecture, documented security practices, and other IT security best practices. As an active ISO/IEC 27001:2022 and ISO 9001:2015 certified organization, Greenbone is dedicated to the most stringent quality standards for Information Security. As an OSS steward, Greenbone is prepared to fulfill the CRA requirements for our OPENVAS community software projects.

Finally, as a vendor of digital products specifically for cyber security, Greenbone’s customers use our OPENVAS line of IT security products to meet their own CRA obligations. This means we are responsible not only for fulfilling our own CRA obligations, but also for understanding the technical needs that other organizations have to stay compliant. This dual role as a manufacturer of digital products and a vendor of cyber security products that help other organizations achieve CRA compliance gives Greenbone a clear vantage point: navigating the regulation while also broadly supporting global manufacturers of digital products to do the same.

Are you ready for the Cyber Resilience Act?

CRA-compliant vulnerability assessments and audits – OPENVAS SECURITY INTELLIGENCE guides you toward compliance, on premises or in the cloud.

➜ Request a consultation now

Recommendations for Software Vendors Working with Open Source

  1. Map your OSS usage. Every open-source component in your products must be identified, documented, and tracked. This is the foundation of your SBOM and is required by the CRA regardless of the component’s own compliance status.
  2. Audit your commercial relationships. If you monetize OSS in any way, such as paid support, SaaS delivery, professional services, seek legal advice on whether full manufacturer obligations apply. The guidance’s monetization test is the place to start.
  3. Prepare for September reporting now. Set up an internal process that can produce a 24-hour early warning — ENISA’s SRP onboarding and registration guidance has been available since 31 July 2026.
  4. Engage with the community. The ORC Working Group maintains a CRA FAQ and resource hub for OSS stewards and manufacturers (cra.orcwg.org and the CRA Hub on GitHub). The OpenSSF is also tracking CRA policy developments.
  5. Review the EC’s guidance. The Commission approved its guidance on applying the CRA on 27 July 2026 (Communication C(2026) 5252 and Annex) — if you assessed your project’s CRA status using the March 2026 draft, revisit that conclusion against the final text, particularly the FOSS and commercial-activity tests.

Read the full guide: The Complete Guide to the EU Cyber Resilience Act – all requirements, timelines, and penalties in one place.

1. Sources European Commission — Cyber Resilience Act (Regulation EU 2024/2847), Official Journal https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
2. European Commission — CRA and open source software policy page
https://digital-strategy.ec.europa.eu/en/policies/cra-open-source
3. European Commission — Draft guidance announcement (3 March 2026)
https://digital-strategy.ec.europa.eu/en/news/commission-publishes-feedback-draft-guidance-assist-companies-applying-cyber-resilience-act
4. European Commission — CRA reporting obligations
https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
5. ENISA — Single Reporting Platform (SRP)
https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
6. Eclipse Foundation ORC Working Group — orcwg.org
https://orcwg.org/
7. ORC Working Group — CRA Hub (FAQ and implementation resources)
https://github.com/orcwg/cra-hub
8. ORC Working Group — White paper: Open Source Software Stewards and the CRA
https://orcwg.org/cra/resources/d3-5-white-paper-on-open-source-software-stewards-and-cra/
9. OpenSSF — EU Cyber Resilience Act policy page
https://openssf.org/public-policy/eu-cyber-resilience-act/
10. OpenSSF — Global Cyber Policy Working Group CRA tracker
https://policy.openssf.org/CRA/
11. European Commission — Communication C(2026) 5252 and Annex: Guidance on the application of the Cyber Resilience Act (27 July 2026)
https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation

Contact Test Now Buy Here Back to Overview
18. June 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-06-18 17:05:462026-08-27 13:59:32Cyber Resilience Act and Open Source Software: What Software Vendors and Stewards Need to Know
Page 3 of 6‹12345›»

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn