KPLNS

מה מנוצל עכשיו — והאם זה נוגע לעסק בישראלWhat is being exploited now — and does it touch a business in Israel

קטלוג הפרצות המנוצלות בפועל של CISA, מסונן לשוק הישראלי ומוסבר בעבריתCISA's exploited-in-the-wild catalogue, filtered for the Israeli market and explained in Hebrew

הדף הזה לא סורק אתכם. הוא לא יודע מה מותקן אצלכם, ולכן לא יכול להגיד לכם שאתם בסדר.
This page does not scan you. It has no idea what you run, so it cannot tell you that you are fine.
עודכן 02/09/2026 19:25 · נבדק פעמיים ביום · 2/2 מקורות נקראוUpdated 02/09/2026 19:25 · checked twice a day · 2/2 sources read
סיכום: רמת החשיפה 0 מתוך 3שבוע שקטSummary: exposure level 0 of 3A quiet week
חשיפת סייבר — ישראלCyber exposure — Israel
לא נוסף השבוע לקטלוג אף מוצר היקפי שנפוץ בישראל.No internet-facing product common in Israel entered the catalogue this week.
5
רשומות חדשות בקטלוג — 7 ימיםNew catalogue entries — 7 days
17
מהן רלוונטיות לשוק הישראלי — 30 יוםOf those, relevant to the Israeli market — 30 days
8
מהן רכיבים היקפיים — 30 יוםOf those, perimeter products — 30 days
1687
סך הרשומות בקטלוג KEVTotal entries in the KEV catalogue

אותות הקשר — מחוץ לרמהContext signals — outside the level

פרצות שכבר שימשו לכופרה (30 יום)Used in ransomware (30 days)הקשרcontext
אין רשומותnone
פרצות במוצר של יצרן ישראלי (90 יום)In a product from an Israeli vendor (90 days)הקשרcontext
3 רשומות3 entries

הרשומות שנספרו כאן:The entries counted here: CVE-2026-66384 CVE-2026-16232 CVE-2026-50751

ניצול צפוי בהיקף רחב — EPSS מעל 50% (30 יום)Wide-scale exploitation expected — EPSS over 50% (30 days)הקשרcontext
6 רשומות6 entries

הרשומות שנספרו כאן:The entries counted here: CVE-2019-1068 CVE-2026-33824 CVE-2026-8037 CVE-2026-63077 CVE-2026-34486 CVE-2026-18577

רכיבים היקפיים שתאריך היעד של CISA להם כבר עבר (30 יום)Perimeter products whose CISA due date has passed (30 days)הקשרcontext
8 רשומות8 entries
ארבע השורות האלה אינן חלק מהרמה, בכוונה. שתיים מהן דולקות כמעט תמיד — תאריך יעד שחלף וציון EPSS גבוה — כי CISA נותנת 3–14 יום לתיקון, וכי רשומה בקטלוג היא מעצם הגדרתה פרצה שכבר מנצלים. אינדיקטור שדולק תמיד אינו אינדיקטור. הן מוצגות כאן כהקשר, לא כציון.
Those four lines are deliberately not part of the level. Two of them are lit almost always — a passed due date and a high EPSS — because CISA allows 3–14 days to patch, and because a catalogue entry is by definition already being exploited. An indicator that is always on is not an indicator. They are shown as context, not as a score.
מקורות:Sources: CISA KEV v2026.09.01 · 1687 entries FIRST.org EPSS
עודכן: Updated: 02/09/2026 19:25 (שעון ישראל) (Israel time)

⚠️ לקרוא לפני שמסיקים מהצבע

⚠️ Read this before reading the colour

מה אומרות הרמות

0 · שבוע שקטלא נוסף השבוע אף מוצר היקפי שנפוץ בישראל. זה המצב השכיח ביותר — 22 מתוך 52 השבועות שנמדדו.
1 · פריט אחדנוסף מוצר היקפי אחד. בדקו אם הוא אצלכם ובאיזו גרסה. 14 מתוך 52 שבועות — זהו השבוע החציוני.
2 · שבוע עמוסשני מוצרים היקפיים בשבוע אחד. 6 מתוך 52 שבועות.
3 · חריגשלושה ומעלה. קרה ב-10 מתוך 52 השבועות שנמדדו — לרוב כשמתפרסם גל תקיפות על ציוד קצה.

הרמה סופרת מוצרים היקפיים בלבד — כאלה שתוקף מחו"ל יכול להגיע אליהם ישירות. פרצה בתחנת עבודה חשובה גם היא, אבל היא לא נספרת ברמה, כי היא דורשת שמישהו אצלכם ילחץ על משהו.

What the levels mean

0 · A quiet weekNo internet-facing product common in Israel was added this week. This is the normal week — 30 of the 52 measured.
1 · One itemOne perimeter product was added. Check whether you run it, and on which version. 10 of 52 weeks.
2 · A busy weekTwo perimeter products in a single week. 3 of 52 weeks.
3 · UnusualThree or more. Happened in 9 of the 52 measured weeks, usually when a wave of edge-device attacks breaks.

The level counts perimeter products only — the ones an attacker abroad can reach directly. A workstation flaw matters too, but it is not in the level, because it needs somebody inside to click something.

מה ברשימה עכשיו — והאם זה נוגע לכם

What is on the list now — and whether it touches you

מסודר לפי: רכיב היקפי לפני פנימי, יצרן נפוץ בישראל לפני פחות נפוץ, פרצה ששימשה לכופרה ו-EPSS גבוה לפני אלה שלא, וחדש לפני ישן. אין משקלות נסתרים. ההסבר בעברית מורכב אך ורק משדות שקיימים ברשומה עצמה — שדה חסר מוריד משפט, ולא ממציא אותו. פתחו שורה עם + לקבלת ההסבר המלא.

Ordered by: perimeter before internal, vendors common in Israel before less common ones, ransomware-linked and high-EPSS before neither, newer before older. No hidden weights. The Hebrew explanation is assembled strictly from fields present in the record — a missing field drops a sentence rather than inventing one. The English line below each entry is CISA's own description. Open a row with + for the full explanation.

SonicWall SMA1000 Appliancesשער גישה מרחוקinternet-facingשימש לכופרהused in ransomware
CVE-2026-15409 · EPSS 84% · נוסף 2026-07-14CVE-2026-15409 · EPSS 84% · added 2026-07-14

SonicWall SMA1000 Appliances הוא שער גישה מרחוק. סוג הפרצה: הכרחת השרת לפנות ליעד פנימי (SSRF). CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 84% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: חומות אש ו-SSL VPN נפוצים מאוד בעסקים קטנים ובינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-17 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Microsoft SharePoint Serverשרת שיתוף מסמכים, לרוב חשוף לאינטרנטinternet-facingשימש לכופרהused in ransomware
CVE-2026-45659 · EPSS 76% · נוסף 2026-07-01CVE-2026-45659 · EPSS 76% · added 2026-07-01

Microsoft SharePoint Server הוא שרת שיתוף מסמכים, לרוב חשוף לאינטרנט. סוג הפרצה: פענוח אובייקט לא מהימן. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 76% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: כמעט כל ארגון בישראל מריץ Windows, Microsoft 365 או שניהם. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-04 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Check Point Security Gatewayשער בקצה הרשתinternet-facingשימש לכופרהused in ransomware🇮🇱 צ'ק פוינט — תל אביבIsraeli vendor
CVE-2026-50751 · EPSS 84% · נוסף 2026-06-08CVE-2026-50751 · EPSS 84% · added 2026-06-08

Check Point Security Gateway הוא שער בקצה הרשת. סוג הפרצה: עקיפת אימות זהות. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 84% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: יצרן ישראלי עם חדירה גבוהה במיוחד בארגונים הגדולים ובמגזר הציבורי בישראל. (הערכה מקצועית, לא מדידה.) יצרן ישראלי — צ'ק פוינט — תל אביב. תאריך היעד של CISA הוא 2026-06-11 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

SonicWall SMA1000 Appliancesשער גישה מרחוקinternet-facingשימש לכופרהused in ransomware
CVE-2026-15410 · EPSS 12% · נוסף 2026-07-14CVE-2026-15410 · EPSS 12% · added 2026-07-14

SonicWall SMA1000 Appliances הוא שער גישה מרחוק. סוג הפרצה: הרצת קוד זר. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 12% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: חומות אש ו-SSL VPN נפוצים מאוד בעסקים קטנים ובינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-17 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Microsoft SharePointשרת שיתוף מסמכים, לרוב חשוף לאינטרנטinternet-facing
CVE-2026-50522 · EPSS 85% · נוסף 2026-07-22CVE-2026-50522 · EPSS 85% · added 2026-07-22

Microsoft SharePoint הוא שרת שיתוף מסמכים, לרוב חשוף לאינטרנט. סוג הפרצה: פענוח אובייקט לא מהימן. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 85% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: כמעט כל ארגון בישראל מריץ Windows, Microsoft 365 או שניהם. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-25 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

WordPress Coreמערכת ניהול תוכן שמריצה אתר אינטרנט חשוףinternet-facing
CVE-2026-60137 · EPSS 78% · נוסף 2026-07-21CVE-2026-60137 · EPSS 78% · added 2026-07-21

WordPress Core הוא מערכת ניהול תוכן שמריצה אתר אינטרנט חשוף. סוג הפרצה: הזרקת SQL. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 78% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: הפלטפורמה שעליה יושבים רוב אתרי העסקים הקטנים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-04 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

WordPress Coreמערכת ניהול תוכן שמריצה אתר אינטרנט חשוףinternet-facing
CVE-2026-63030 · EPSS 97% · נוסף 2026-07-21CVE-2026-63030 · EPSS 97% · added 2026-07-21

WordPress Core הוא מערכת ניהול תוכן שמריצה אתר אינטרנט חשוף. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 97% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: הפלטפורמה שעליה יושבים רוב אתרי העסקים הקטנים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-24 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Fortinet FortiSandboxמערכת ניתוח קבצים בפריסת רשתinternet-facing
CVE-2026-25089 · EPSS 76% · נוסף 2026-07-16CVE-2026-25089 · EPSS 76% · added 2026-07-16

Fortinet FortiSandbox הוא מערכת ניתוח קבצים בפריסת רשת. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 76% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: FortiGate היא אחת מחומות האש הנפוצות ביותר בשוק העסקים הקטנים והבינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-19 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Fortinet FortiSandboxמערכת ניתוח קבצים בפריסת רשתinternet-facing
CVE-2026-39808 · EPSS 93% · נוסף 2026-07-16CVE-2026-39808 · EPSS 93% · added 2026-07-16

Fortinet FortiSandbox הוא מערכת ניתוח קבצים בפריסת רשת. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 93% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: FortiGate היא אחת מחומות האש הנפוצות ביותר בשוק העסקים הקטנים והבינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-19 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Ivanti Sentryשער אבטחה למכשירים ניידיםinternet-facing
CVE-2026-10520 · EPSS 100% · נוסף 2026-06-11CVE-2026-10520 · EPSS 100% · added 2026-06-11

Ivanti Sentry הוא שער אבטחה למכשירים ניידים. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 100% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: שערי גישה מרחוק וניהול מכשירים; יעד חוזר ונשנה של תקיפות בעולם ובישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-06-14 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Citrix NetScaler ADC and NetScaler Gatewayשער גישה מרחוק / מאזן עומסיםinternet-facing
CVE-2026-8452 · EPSS 2% · נוסף 2026-08-26CVE-2026-8452 · EPSS 2% · added 2026-08-26

Citrix NetScaler ADC and NetScaler Gateway הוא שער גישה מרחוק / מאזן עומסים. סוג הפרצה: חריגה מגבולות זיכרון. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 2% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: NetScaler וגישה מרחוק — נפוץ בבריאות, בפיננסים ובממשלה. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-29 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Synacor Zimbra Collaboration Suite (ZCS)שרת דואר ושיתוף פעולהinternet-facing
CVE-2026-73570 · EPSS 21% · נוסף 2026-08-21CVE-2026-73570 · EPSS 21% · added 2026-08-21

Synacor Zimbra Collaboration Suite (ZCS) הוא שרת דואר ושיתוף פעולה. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 21% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: המוצר הוא Zimbra — שרת דואר שנפוץ בישראל במוסדות אקדמיים, ברשויות מקומיות ובעסקים שלא עברו ל-Exchange. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-24 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as published

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

מגמת הרמה — 7 הימים האחרונים

ציר Y: הרמה (0–3) — 0 רגוע, 3 קריטי. ציר X: זמן אמת, שעון ישראל.

רמת חשיפה · כעת 0אין נתונים

Level over time — the last 7 days

Y axis: the level (0–3) — 0 calm, 3 critical. X axis: real time, Israel time.

Exposure level · now 0no data

החלון קבוע על 7 ימים גם כשההיסטוריה קצרה ממנו, כדי שלא ייווצר רושם שהמערכת מודדת כבר שבוע. בחלון הזה יש 14 דגימות אמיתיות, הראשונה ב-27/08/2026 07:25 והאחרונה ב-02/09/2026 19:25. הקו הוא קו מדרגה: רמה מוצגת כמוחזקת מרגע המדידה ועד המדידה הבאה. אין החלקה, אין ממוצע ואין נקודות מומצאות — כל קודקוד בקו הוא שורה שקיימת בקובץ הנתונים. פער של יותר מ-13 שעות בין דגימות נחתך בקו ומסומן בהצללה: חור בנתונים אינו רגיעה.

The window stays fixed at 7 days even when the history is shorter, so the page never implies it has been measuring all week. This window holds 14 real samples, the first at 27/08/2026 07:25 and the last at 02/09/2026 19:25. The line is a step line: a level is drawn as held from the sample that measured it until the next one. No smoothing, no averaging, no invented points — every vertex is a row that exists in the data file. A gap of more than 13 hours between samples cuts the line and is hatched: a hole in the data is not calm.

איך זה עובד, בקצרה

הדף קורא פעמיים ביום את קטלוג CISA KEV — רשימת הפרצות שCISA אישרה שמנוצלות בפועל בתקיפות, לא תיאורטית. הקטלוג הוא ציבורי, ללא מפתח, ומכיל אלפי רשומות שרובן חסרות משמעות לקורא ישראלי.

מכאן הכול נמצא בסינון. לכל רשומה מחושבות שלוש תכונות נפרדות, ובכוונה לא באותה רמת ודאות:

הרמה 0–3 היא ספירה אחת ויחידה: כמה מוצרים היקפיים שנפוצים בישראל נוספו לקטלוג ב-7 הימים האחרונים. הספים לא נוחשו — הם נקבעו אחרי מדידה של 52 השבועות הקודמים על הקטלוג האמיתי.

למתודולוגיה המלאה, כולל מה נבדק ונפסל ←

How this works, briefly

Twice a day the page reads the CISA KEV catalogue — the list of vulnerabilities CISA has confirmed are being exploited in real attacks, not theoretically. It is public, keyless, and holds thousands of entries, most of them meaningless to an Israeli reader.

Everything from there is the filter. Each entry gets three separate properties, deliberately not at the same level of certainty:

The 0–3 level is one single count: how many perimeter products common in Israel entered the catalogue in the last 7 days. The thresholds were not guessed — they were set after measuring the previous 52 weeks against the real catalogue.

Full methodology, including what was tested and rejected →