logo

CISA’s secure-software buying tool had a simple XSS vulnerability of its own

ID: 21c9aeaa-34e5-5411-ba5d-d7443eda8cee

STIX ID: report--21c9aeaa-34e5-5411-ba5d-d7443eda8cee

Feed Name: CyberScoop

Threat Score
30/100

Date Published: 2026-01-15

Date Updated: 2026-04-21

Author: Tim Starks

...
...

#### Executive summary — CISA's Software Acquisition Guide: Supplier Response Web Tool contained a cross-site scripting (XSS) vulnerability that was reported in September and patched in December; there is no evidence of known exploitation, and the agency followed coordinated disclosure procedures to create a CVE and apply a fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.