Skip to content

Design prototype. Figures, officials, and events are illustrative placeholders, not live data.

DDD
Critical Infrastructure

Communications and Cyber

Several actively exploited vulnerabilities in widely used software; agencies urge rapid patching.
Strained
Updated

Why this is rated strained

CISA added an above-average number of vulnerabilities to its exploited catalog this month, including flaws in network edge devices used by utilities and local governments.

Strained: Meaningful stress or a near-term risk of disruption. Some functions may be degraded. Methodology

About this area

Tracks significant cyber incidents, CISA advisories, and telecommunications outages.

Indicators

Latest readings. Changes are shown without judgment of whether up or down is better.

IndicatorLatest

Exploited vulnerabilities added (30-day)

Source: Cybersecurity and Infrastructure Security Agency
27CVEs

Joint advisories issued (30-day)

Source: Cybersecurity and Infrastructure Security Agency
6advisories

Reported major telecom outages (30-day)

Source: Federal Communications Commission
2events

Charts

Exploited vulnerabilities added (30-day)27CVEs
Source: Cybersecurity and Infrastructure Security Agency

Timeline of developments

  1. Emergency directive issued for VPN appliance flaw

    Federal agencies were directed to patch or disconnect affected devices within 72 hours after reports of active exploitation.

    Source: Cybersecurity and Infrastructure Security Agency
  2. Joint advisory on intrusions targeting water utilities

    US and allied agencies described tactics used against internet-exposed industrial control systems.

    Source: Cybersecurity and Infrastructure Security Agency

Sources and citations

  1. 1.
    Known Exploited Vulnerabilities Catalog

    Cybersecurity and Infrastructure Security Agency. Accessed Sep 27, 2026.

  2. 2.
    Cybersecurity advisories

    Cybersecurity and Infrastructure Security Agency. Accessed Sep 27, 2026.

  3. 3.
    Disaster Information Reporting System

    Federal Communications Commission. Accessed Sep 27, 2026.

See something that looks wrong? Report an inaccuracy