Author: Osiris

  • Researcher ‘Nightmare Eclipse’ Drops Three Zero-Day Exploits for CrowdStrike, Nvidia and Avast

    Researcher ‘Nightmare Eclipse’ Drops Three Zero-Day Exploits for CrowdStrike, Nvidia and Avast

    A security researcher who goes by the handle Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare and MSNightmare, published three new zero-day proof-of-concept exploits within a single week, targeting security and driver software from Avast, CrowdStrike and Nvidia.

    Three Exploits, Three Vendors

    The first, dubbed PrettyPrague, targets the sandbox used by Avast Antivirus to spawn a shell with full system privileges, and the researcher says it may also affect other GenDigital products, including AVG and Norton. A GenDigital spokesperson told SecurityWeek the company was made aware of the issue, initiated its security response procedures, and has fixed it.

    The second, FalconFlank, exploits a bug in the Office malicious-macro remediation feature of CrowdStrike Falcon Sensor to escalate privileges. CrowdStrike said it is actively investigating the claims and has advised customers to disable a related Windows policy setting while pointing to guidance in its support portal.

    The third, GreenSection, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode display driver components on Windows. Nvidia said it is reviewing the reported behavior through its established security processes.

    Part of a Broader Pattern

    Nightmare Eclipse became known for a series of zero-day exploits targeting Microsoft products before expanding to other vendors. In late August, the researcher released a separate privilege-escalation zero-day affecting a Kaspersky endpoint security product, which Kaspersky patched on Aug. 31. Independent security researcher Kevin Beaumont said he had confirmed that the Avast, CrowdStrike and Kaspersky exploits work as described.

    None of the three latest exploits are confirmed to grant SYSTEM-level access on their own; each requires local code execution as a starting point and functions as a privilege-escalation primitive rather than a full remote compromise chain. All three vendors said they are investigating or have already issued fixes.

  • Thermal Cameras Beyond Perimeter Protection

    Thermal Cameras Beyond Perimeter Protection

    Thermal cameras have long been associated with a single job in physical security: spotting intruders along a dark perimeter where visible-light cameras struggle. That reputation undersells the technology. Because thermal imaging detects heat rather than reflected light, it has found a growing set of applications well beyond perimeter intrusion detection.

    Why Thermal Works Where Visible Light Fails

    A thermal, or infrared, camera does not capture light in the way a conventional camera does. It measures the infrared radiation every object emits based on its temperature and converts that data into a visible image. Because it does not rely on ambient or artificial light, a thermal camera performs consistently in total darkness, through smoke, light fog and other conditions that degrade visible-light imaging, which is the original basis for its use along fences and open perimeters.

    Early Fire and Overheat Detection

    Because thermal cameras measure temperature directly, they can identify a developing fire or equipment overheating before flames or smoke are visible to a conventional camera or even to a person on site. This has made thermal imaging a growing complement to traditional smoke and heat detectors in settings like waste and recycling facilities, warehouses storing combustible materials, and outdoor stockpiles at industrial sites, where a slow-building fire in a large pile of material can go undetected by point smoke detectors for hours.

    Industrial Condition Monitoring

    Fixed thermal cameras are increasingly used for continuous monitoring of industrial equipment such as electrical switchgear, transformers, motors and bearings, where an abnormal temperature rise can be an early indicator of a developing fault. Unlike a handheld thermal camera used for periodic inspection, a fixed unit can watch critical equipment continuously and trigger an alert as soon as a reading crosses a defined threshold, extending thermal imaging from a security tool into a predictive-maintenance and safety tool.

    Health and Occupancy Screening

    Thermal cameras also saw expanded use for elevated-temperature screening at building entrances, though public health authorities and manufacturers alike have cautioned that a thermal camera at a doorway is a coarse screening tool rather than a diagnostic one, since ambient temperature, camera calibration and where on the face the reading is taken all affect accuracy. More durable applications in this space include monitoring processing areas in food and pharmaceutical facilities, where consistent thermal conditions matter for product safety and equipment performance.

    Combining Thermal With Analytics

    Modern thermal cameras increasingly pair with the same AI-based analytics used on visible-light cameras, applying object classification and behavioral detection to the thermal image. This combination is particularly useful for outdoor perimeter and critical-infrastructure sites, where a thermal-plus-analytics camera can both detect a person or vehicle in total darkness and classify what it has detected, reducing false alarms compared with older thermal systems that could only flag a change in the scene without saying what caused it.

    FAQ

    Can thermal cameras replace smoke detectors? No. Thermal cameras are generally deployed as a complement to, not a replacement for, code-required smoke and heat detection systems, particularly useful for large or open areas where point detectors are impractical or too slow.

    Do thermal cameras work in daylight? Yes. Thermal imaging is based on heat rather than visible light, so it functions in bright daylight, complete darkness and through smoke or light fog alike, unlike visible-light cameras.

    Are thermal cameras accurate for measuring exact temperatures? Radiometric thermal cameras can provide calibrated temperature readings suitable for industrial monitoring, but accuracy depends on calibration, distance and environmental conditions, and screening-grade thermal cameras are generally not precise enough for medical-grade temperature measurement.

  • AI Video Analytics: What Actually Works?

    AI Video Analytics: What Actually Works?

    Marketing around AI video analytics often implies a single, uniformly capable technology. In practice, “AI video analytics” covers a range of distinct tasks with very different levels of real-world maturity, from tasks that are now routinely reliable to others that remain error-prone outside controlled conditions. Understanding that range matters for anyone deciding what to actually deploy and trust.

    Well-Established: Object Classification and Counting

    Detecting and classifying broad object categories, such as person, vehicle or bag, is now a mature capability across most commercial video analytics products, built on deep-learning models trained on large, diverse image datasets. People counting and basic line-crossing or zone-intrusion detection built on this foundation are generally reliable in typical lighting and camera-placement conditions, which is why these features have become standard rather than premium additions on many camera and VMS platforms.

    Increasingly Reliable: License Plate Recognition

    Automatic license plate recognition has matured considerably and performs well under favorable conditions: adequate lighting, a reasonably direct camera angle and moderate vehicle speed. Performance still degrades with poor lighting, extreme angles, dirty or damaged plates, and regional plate formats the underlying model was not trained on, which is why plate-recognition systems are typically deployed with purpose-selected cameras and lenses rather than repurposed general-surveillance cameras.

    Mixed Results: Behavioral and Anomaly Detection

    Detecting behaviors such as loitering, fighting, or a person falling is harder than classifying static objects because it requires interpreting motion and context over time, and there is far less standardized training data for rare or unusual events than for common objects like people and cars. Vendors have made real progress here, but false-positive and false-negative rates for behavioral analytics remain noticeably higher than for basic object detection, and performance is more sensitive to camera angle, crowd density and scene complexity.

    Still Immature for Many Deployments: Facial Recognition at Scale

    Facial recognition accuracy has improved substantially in laboratory testing, but real-world performance depends heavily on image quality, angle, lighting and the size and diversity of the reference database being matched against. Independent testing bodies, including the U.S. National Institute of Standards and Technology, have documented accuracy differences across demographic groups for some algorithms, which is part of why facial recognition deployment in public and semi-public spaces continues to draw closer regulatory scrutiny than other forms of video analytics.

    The Common Thread: Conditions Matter More Than Marketing

    Across all of these categories, the gap between vendor demonstration performance and field performance usually comes down to conditions: camera placement, lighting, resolution, frame rate, scene complexity and how closely the deployment environment matches the data the underlying model was trained on. Security teams evaluating AI video analytics get more reliable results by piloting a product in their actual environment before wide deployment than by relying on vendor-reported accuracy figures alone, since those figures are typically generated under favorable test conditions.

    FAQ

    Which AI video analytics feature is most reliable today? Basic object classification — distinguishing people, vehicles and similar broad categories — is generally the most mature and consistently reliable analytics capability across vendors.

    Why do vendor accuracy claims sometimes not match real-world results? Vendor figures are often measured under favorable test conditions. Real deployments introduce variables like lighting changes, camera angle, weather and scene clutter that reduce accuracy compared with controlled testing.

    Should organizations pilot AI analytics before full deployment? Yes. Because performance is highly condition-dependent, testing analytics in the actual deployment environment is the most reliable way to validate accuracy before committing to a wide rollout.

  • From CCTV to Video Intelligence: The Evolution of Surveillance

    From CCTV to Video Intelligence: The Evolution of Surveillance

    The term CCTV, short for closed-circuit television, describes a technology that has changed almost beyond recognition since it first appeared in commercial security. What began as a closed loop of cameras feeding a bank of monitors and videotape recorders has become a distributed, searchable intelligence system. Tracing that evolution helps explain why the industry increasingly talks about “video intelligence” rather than simply surveillance.

    The Analog Era: Recording Without Searching

    Early CCTV systems recorded continuously to videotape, which had to be physically swapped, stored and, when needed, reviewed in real time by fast-forwarding through hours of footage. There was no way to search for a specific event other than knowing roughly when it occurred and manually scrubbing through the tape. Coverage was also limited by cost and cabling; each camera required a dedicated coaxial run back to a central recorder.

    Digital Video Recording and IP Cameras

    Digital video recorders (DVRs) replaced tape with hard drives, letting operators jump to a timestamp instantly rather than fast-forwarding physical media. The shift to IP cameras that transmit over standard computer networks further loosened the physical constraints of analog systems, allowing cameras to be added, moved or networked across sites without dedicated coaxial cabling, and enabling remote viewing over the internet for the first time.

    Video Management Systems Bring Structure

    As camera counts grew, video management system (VMS) software became necessary to organize feeds, manage storage, control user access and provide a single interface for monitoring and playback across potentially hundreds of cameras. VMS platforms introduced features like camera health monitoring, role-based access for operators, and integration with access control and alarm systems, turning a collection of individual cameras into a managed security infrastructure.

    Analytics Turn Video Into Searchable Data

    The more recent shift toward video intelligence comes from AI-based video analytics that extract structured information from footage: object classification, license plate recognition, people counting, and behavioral patterns such as loitering or wrong-way movement. Instead of reviewing footage sequentially, an investigator can now search by object type, color, direction of travel or, increasingly, natural-language description, retrieving relevant clips in seconds rather than hours. This is the functional definition of video intelligence: video that has been indexed and made queryable, rather than simply archived.

    From Reactive Review to Proactive Alerting

    Video intelligence has also shifted surveillance from a largely reactive tool, used mainly to investigate incidents after the fact, toward a proactive one that can generate real-time alerts for defined conditions, such as a person entering a restricted zone after hours or a vehicle stopped in a fire lane. That shift depends on the analytics running continuously against live video rather than only against recorded footage, which is part of why edge AI processing on cameras themselves has become an important complement to server-based video intelligence platforms.

    FAQ

    Is CCTV an outdated term? The term persists in everyday use, but modern systems typically use IP-based digital cameras, networked recording and AI-based analytics rather than the closed coaxial-cable loops the term originally described.

    What is the difference between a VMS and video analytics? A VMS manages recording, storage, access and playback across cameras. Video analytics is software, often running within or alongside a VMS, that interprets the content of the video to detect and classify objects and events.

    Does video intelligence require replacing existing cameras? Not always. Many video intelligence features can run as software layered on top of existing IP cameras and VMS platforms, though the accuracy and range of available analytics generally improve with cameras that include onboard processing.

  • Edge AI Cameras: How Cameras Became Intelligent Sensors

    Edge AI Cameras: How Cameras Became Intelligent Sensors

    For most of the history of video surveillance, a camera’s job ended at capturing an image. Analysis, if it happened at all, took place later, either by a person reviewing footage or by a server crunching video after the fact. Edge AI has changed that division of labor, moving detection and classification directly onto the camera itself, at the moment the image is captured.

    What ‘Edge’ Means in This Context

    In computing generally, the “edge” refers to processing that happens close to where data is generated, rather than in a centralized data center or cloud. For a security camera, that means running analytics on a chip inside the camera housing rather than streaming raw video to a server or the cloud for processing. The camera itself decides, in real time, whether a frame contains a person, a vehicle, a package left behind, or a fence line being crossed.

    From Motion Detection to Object Understanding

    Early “smart” cameras offered motion detection based on pixel change between frames, a technique that could not distinguish a person from a blowing tree branch or a passing cloud shadow. The generation of onboard neural processing units now built into many commercial cameras allows the device to run a trained deep-learning model directly on the video stream, classifying objects by type and often by attributes such as clothing color or vehicle type, without sending the video anywhere for that first pass of analysis.

    Why Processing at the Camera Matters

    Doing this work on the camera rather than centrally offers several practical advantages. It reduces the bandwidth needed to move video across a network, since only metadata or short alert clips, rather than continuous full-resolution streams, may need to travel to a central system. It also cuts the latency between an event happening and an alert being generated, which matters for use cases like perimeter intrusion or wrong-way vehicle detection where seconds count. Finally, running detection locally can reduce dependence on a live network or cloud connection, letting a camera continue generating alerts even if connectivity to a central server is temporarily lost.

    Metadata as the New Output

    Perhaps the more significant shift is that edge AI cameras produce structured metadata alongside video: timestamps, object classifications, bounding boxes, and sometimes attributes like direction of travel. That metadata can be indexed and searched far more efficiently than raw video, which is what makes features like natural-language video search and cross-camera object tracking practical at scale. In effect, the camera has become a sensor that reports both an image and a description of what it saw, rather than a device that only reports an image.

    Limitations Worth Understanding

    Edge processing is not a universal upgrade. Cameras with onboard AI chips generally cost more than conventional models, and the accuracy of onboard detection depends heavily on the quality and diversity of the training data behind the model, along with factors like camera placement, lighting and weather. Organizations evaluating edge AI cameras typically still pair them with a video management system capable of aggregating and correlating metadata across many devices, since a single camera’s local intelligence is most useful when it feeds into a broader security picture.

    FAQ

    Do edge AI cameras still send video to a server? Usually yes, for recording and human review, but the initial detection and classification happen on the camera, which can reduce how much video needs to be analyzed centrally in real time.

    Are edge AI cameras more accurate than server-based analytics? Not inherently. Accuracy depends on the underlying AI model and training data, not simply on where the processing happens. Edge processing is primarily a bandwidth, latency and resilience advantage.

    Can existing cameras be upgraded to edge AI without replacement? Some manufacturers offer firmware updates that add basic analytics to existing camera lines, but full onboard neural processing generally requires camera hardware built with a dedicated AI chip.

  • Security Screening Technologies Explained: X-Ray, CT and AI Detection Systems

    Security Screening Technologies Explained: X-Ray, CT and AI Detection Systems

    Security screening sits at the entry point of airports, courthouses, stadiums, schools and corporate campuses, tasked with finding weapons, explosives and other prohibited items before they reach a protected space. The technology behind that job has moved well beyond the single-view X-ray machine, now combining several imaging and detection methods, often stitched together with AI-based image analysis.

    X-Ray Imaging: The Foundation

    Conventional X-ray screening remains the backbone of checkpoint security for bags and parcels. Dual-energy X-ray systems distinguish organic materials, such as explosives, from inorganic ones, such as metal, by measuring how differently two X-ray energy levels are absorbed by an object. Operators view color-coded images where organic, inorganic and mixed materials appear in different hues, helping them spot items that warrant a closer look.

    Computed Tomography Adds a Third Dimension

    Computed tomography (CT) scanning, long used in medical imaging, has moved into checkpoint security because it captures a full 3D image of a bag’s contents rather than a flat 2D projection. A CT scanner rotates an X-ray source and detector array around the object, reconstructing a volumetric image that can be rotated and examined from any angle. This additional depth of information is a major reason aviation security programs in the United States, the European Union and elsewhere have pushed to replace older 2D X-ray checkpoint lanes with CT-based lanes, since 3D imaging makes it easier to isolate the shape and density of a suspicious item without the operator needing to ask a traveler to remove it from the bag.

    Millimeter Wave and Body Scanning

    For screening people rather than bags, millimeter wave scanners have become the standard alternative to metal detectors at many checkpoints. These scanners bounce low-energy electromagnetic waves off the body and surrounding clothing, building an image that can reveal non-metallic items, such as ceramic weapons or plastic explosives, that a traditional walk-through metal detector would miss. Automated target recognition software increasingly processes that image directly, flagging areas of concern on a generic body outline rather than displaying a detailed image of the person, which addresses a long-standing privacy objection to earlier body-scanning technology.

    Where AI Fits Into Screening

    Artificial intelligence has entered checkpoint screening primarily as an assistant to human operators rather than a replacement for them. AI-based automatic threat recognition software, trained on large libraries of scanned images, highlights or outlines items in an X-ray or CT image that match the visual signature of prohibited items, such as firearms or explosive shapes. Vendors and regulators generally frame this as a way to reduce operator fatigue and inconsistency across long shifts, rather than as a fully autonomous decision system; a human screener typically still makes the final call on whether a flagged bag needs secondary inspection.

    Trace Detection and Complementary Methods

    Screening programs typically layer imaging technologies with trace detection, which identifies microscopic particles of explosive residue on a swab taken from a bag, laptop or hand. Some checkpoints also use chemical vapor detection to sample the air around a bag or person. These methods do not replace imaging but add a second, independent detection layer that can catch threats an X-ray or CT image alone might not clearly reveal, such as explosive residue on the outside of an otherwise unremarkable item.

    FAQ

    Is CT screening only used in aviation? No. While aviation checkpoints have driven much of the recent investment in CT-based screening, similar imaging systems are used in courthouses, government buildings, correctional facilities and some large venues.

    Does AI screening replace human operators? Not currently. AI automatic threat recognition tools are generally deployed to flag likely threats for a human operator to review, rather than to make autonomous accept/reject decisions.

    Are millimeter wave scanners safe? Millimeter wave technology uses non-ionizing radio frequency energy at power levels regulators consider safe for repeated screening, unlike ionizing technologies such as X-ray, which is why walk-through millimeter wave scanners are used directly on people while X-ray and CT are reserved for bags and cargo.

  • Rapid Response Monitoring Expands Henderson, Nevada Facility, Plans 75 New Jobs

    Rapid Response Monitoring Expands Henderson, Nevada Facility, Plans 75 New Jobs

    Rapid Response Monitoring Services is expanding its central-station operations in Henderson, Nevada, adding roughly 12,000 square feet of leased space and planning to create 75 full-time jobs at the facility over the next two years.

    Investment in Local Operations

    The expansion includes tenant improvements and a $600,000 capital investment in equipment and facility upgrades. The new hiring is expected to grow the Henderson site’s headcount to approximately 240 employees supporting the company’s nationwide Response Management Platform.

    Founded in 1992 and headquartered in Syracuse, New York, Rapid Response protects more than 4 million subscriber accounts across the United States and Canada, combining monitoring technology, artificial intelligence and trained response specialists to process alarm signals and coordinate emergency response.

    “Nevada represents an important part of Rapid’s long-term growth strategy,” said David Pida, chief financial officer at Rapid Response Monitoring. “As the company expands its operational footprint in the state, Rapid is committed to creating high-quality careers, investing in advanced technology, and building lasting partnerships that contribute to the economic vitality of the communities it serves.”

    A Welcome Addition for the City

    Henderson Mayor Michelle Romero welcomed the continued investment, saying it reinforces the city’s position as a destination for business growth. “Their continued growth strengthens our local economy, creates valuable job opportunities, and reinforces Henderson as a premier destination for business,” Romero said.

  • Overhead Door Corp. Acquires Motion Access, Expanding Horton’s Pedestrian Access Business

    Overhead Door Corp. Acquires Motion Access, Expanding Horton’s Pedestrian Access Business

    Overhead Door Corp. has acquired the assets of Motion Access, an Elk Grove Village, Illinois-based provider of automatic pedestrian door operators, replacement parts, retrofit solutions and rebuilt equipment. Motion Access will continue operating under its existing name as part of Horton Automatics, the premium access brand within Horton Pedestrian Access Solutions, a division of Overhead Door Corp.

    Strengthening Aftermarket and Service Capacity

    Overhead Door said the deal expands Horton’s aftermarket, service and retrofit capabilities for automatic pedestrian door solutions across North America, adding a company that has built its reputation serving automatic door professionals nationwide.

    “Motion Access has earned a reputation as a trusted provider of automatic entrance solutions, and we are excited to welcome their team into the Horton family,” said Kelly Terry, president and CEO of Overhead Door Corp. “This acquisition strengthens our aftermarket and service capabilities, expands our product offering, and reinforces our commitment to delivering innovative solutions and exceptional support to customers throughout North America.”

    Motion Access owners Joseph Madden, Robert Oakley, Gilbert Valencia and Michael Valencia said in a joint statement that finding the right long-term home for the business was one of the most important decisions they had made as owners, and that joining Horton creates new opportunities for employees and customers.

    Part of a Broader Pedestrian Access Portfolio

    Horton Pedestrian Access Solutions, which also operates the WonDoor brand, runs multiple manufacturing and service locations and works with more than 200 distribution partners across North America. Lewisville, Texas-based Overhead Door Corp., a subsidiary of Tokyo-based Sanwa Holdings Corp., serves more than 4,500 professional distribution partners across residential, commercial, institutional and industrial access markets.

  • Epson and STOPware Partner on On-Demand Color Visitor Badge Printing

    Epson and STOPware Partner on On-Demand Color Visitor Badge Printing

    Epson and visitor management software provider STOPware have announced a partnership integrating Epson’s ColorWorks on-demand color printing technology with STOPware’s PassagePoint platform, allowing organizations to produce full-color, photo-ready visitor badges in real time at sign-in.

    Color as a Security and Workflow Tool

    The integration pairs Epson’s CW-C4000 and CW-C6000 ColorWorks printers with PassagePoint to generate badges featuring visitor photos, color-coded access levels, department or zone identifiers, branding elements, and QR codes or barcodes for check-in, check-out tracking and access control integration.

    According to the companies, color coding helps front-line staff quickly distinguish visitors, contractors, vendors and temporary staff, and can visually flag which building zones a given badge is authorized to access. Full-color photos on the badge itself are also intended to reduce the risk of badge cloning or reuse.

    “We’re seeing firsthand that on-demand, full-color badge printing can help enable safer and faster access decisions, especially in high-traffic environments like hospitals, schools, corporate campuses or government facilities,” said Michael Weitz, product manager for ColorWorks at Epson America.

    Removing Pre-Printed Badge Inventory

    Because badges are printed on demand rather than drawn from pre-printed stock, organizations using the integration no longer need to maintain separate badge inventories or manually restock supplies, and every badge reflects current visit information and access policy.

    “Visitor badges are a frontline tool in ensuring building safety,” said Debbie Pendleton, chief operating officer of STOPware. “By combining ColorWorks color printing technology with STOPware’s platform, organizations gain instantaneous visual clarity and robust identification without slowing down visitor flow.”

  • CISA Flags Active Exploitation of LiteLLM and Starlette Flaws in First AI-Heavy KEV Batch

    CISA Flags Active Exploitation of LiteLLM and Starlette Flaws in First AI-Heavy KEV Batch

    The Cybersecurity and Infrastructure Security Agency added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on Sept. 2, 2026, based on evidence of active exploitation. Three of the seven affect artificial intelligence and machine learning infrastructure — the first KEV batch in which AI-related components make up nearly half the additions.

    Authentication Bypass in a Widely Used AI Gateway

    The most significant of the AI-related entries is CVE-2026-59822, an improper-authentication flaw in LiteLLM, an open-source proxy server that routes calls to large language model APIs. According to the National Vulnerability Database, versions of LiteLLM prior to 1.84.0 allowed an unauthenticated attacker to submit a fabricated bearer token to the product’s Model Context Protocol Streamable HTTP endpoint, triggering an OAuth2 fallback path that granted access without a valid key. The flaw is fixed in version 1.84.0 and carries a CVSS score of 8.8.

    CISA also added CVE-2026-48710, an HTTP request/response smuggling vulnerability in the Starlette web framework that underlies the popular FastAPI toolkit used to build many AI agent and API services. Because Starlette typically ships as a transitive dependency of FastAPI rather than a direct one, researchers tracking the issue note it rarely appears in software inventories, making dependency lockfile scanning the more reliable way to detect exposure. A third AI-adjacent flaw affects JFrog Artifactory, a package repository manager widely used in AI development pipelines to store and distribute models and dependencies.

    Agentic Infrastructure Becomes a Target

    Security researchers at Microsoft and Wiz say the exploitation activity reflects a broader shift toward targeting AI infrastructure components — including LLM gateways, vector databases and MCP servers — to steal API keys, gain backend access, and monetize compromised hosts, in some cases through cryptocurrency mining.

    Under Binding Operational Directive 26-04, federal civilian agencies must remediate most of the newly added vulnerabilities by Sept. 5, 2026, while the Starlette and LiteLLM flaws carry a Sept. 16, 2026 deadline. CISA continues to recommend that all organizations, not just federal agencies, prioritize patching KEV Catalog entries as part of routine vulnerability management.