| CVE | Check / Plugin | Asset | Port | Severity | State | KEV | Days to Due | First Seen | ★ |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-12345 | Apache Log4j Remote Code Execution | WEB-PROD-03 | 443/tcp | Critical | Active | ⚠ | 2026-02-14 | ☆ | |
| CVE-2026-11223 | Windows Print Spooler Elevation | DC-PROD-01 | 445/tcp | High | Active | ⚠ | 2026-01-08 | ★ | |
| CVE-2026-09876 | OpenSSL X.509 Certificate Parsing | APP-PROD-07 | 8443/tcp | Medium | Active | 2025-11-20 | ☆ | ||
| CVE-2026-04567 | Linux Kernel Privilege Escalation | DB-PROD-02 | 22/tcp | High | Active | 2026-03-05 | ☆ | ||
| CVE-2026-33445 | Microsoft Exchange Server RCE | EXCH-PROD-01 | 443/tcp | Critical | Fixed | ⚠ | 2026-04-12 | ★ |
📊 Security Posture Overview
Apache Log4j Remote Code Execution (Log4Shell)
Apache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
| Asset | Check / Plugin | Port | State | Status | Owner | First Seen | Last Observed |
|---|---|---|---|---|---|---|---|
| WEB-PROD-03 | Apache Log4j Remote Code Execution | 443/tcp | Active | Open | jsmith | 2026-02-14 | 2026-06-28 |
| WEB-PROD-07 | Apache Log4j Remote Code Execution | 443/tcp | Active | Open | — | 2026-02-14 | 2026-06-28 |
| APP-PROD-02 | Log4j Detected (Windows Agent) | 8080/tcp | Active | Risk Accepted | mwilson | 2026-03-01 | 2026-06-27 |
| APP-PROD-05 | Apache Log4j (Linux RPM Check) | 8080/tcp | Active | Open | — | 2026-03-15 | 2026-06-28 |
| ADMIN-DEV-01 | Log4j Vulnerability Scan (Scanner) | 8443/tcp | Active | Open | — | 2026-04-20 | 2026-06-25 |
| Asset | IP | OS | EOL Status | Site | Owner | Active CVEs | Critical | High | Last Seen |
|---|---|---|---|---|---|---|---|---|---|
| WEB-PROD-03 | 10.23.4.17 | Ubuntu 22.04 LTS | ✅ Supported | US-East (nyc1) | Platform Engineering | 47 | 3 | 14 | 2026-06-28 |
| DC-PROD-01 | 10.23.1.4 | Windows Server 2022 | ✅ Supported | US-East (nyc1) | Infrastructure | 32 | 5 | 11 | 2026-06-27 |
| DB-PROD-02 | 10.23.8.55 | RHEL 9.3 | ✅ Supported | EU-Central (fra1) | Database & Storage | 28 | 2 | 8 | 2026-06-28 |
| EXCH-PROD-01 | 10.23.2.12 | Windows Server 2022 | ✅ Supported | US-West (sfo1) | Infrastructure | 19 | 1 | 6 | 2026-06-26 |
| APP-PROD-07 | 10.23.5.88 | Ubuntu 22.04 LTS | ✅ Supported | US-East (nyc1) | Application Services | 41 | 4 | 12 | 2026-06-28 |
| Solution / Remediation | CVEs | Assets | Severity Range | |
|---|---|---|---|---|
| Upgrade Apache Log4j to version 2.17.1 or later | 2 | 12 | Critical | |
| Apply Microsoft Security Update KB5012345 for Print Spooler | 3 | 34 | High | |
| Upgrade OpenSSL to 3.0.12+ / 1.1.1w+ | 5 | 18 | Medium | |
| Deploy updated kernel package: linux-image-5.15.0-91-generic | 4 | 22 | High | |
| Install Microsoft Exchange Server SU CU23 Jan 2026 | 1 | 3 | Critical |
Infrastructure
Core network, domain controllers, DNS, DHCP
Scope: tags env=production function=infra | Sites: US-East, US-West, EU-Central
| Asset | IP | OS | Site | Active CVEs | Critical | High | Last Seen |
|---|---|---|---|---|---|---|---|
| DC-PROD-01 | 10.23.1.4 | Windows Server 2022 | US-East (nyc1) | 32 | 5 | 11 | 2026-06-27 |
| DC-PROD-02 | 10.23.1.5 | Windows Server 2022 | US-East (nyc1) | 28 | 4 | 9 | 2026-06-28 |
| EXCH-PROD-01 | 10.23.2.12 | Windows Server 2022 | US-West (sfo1) | 19 | 1 | 6 | 2026-06-26 |
| DNS-PROD-01 | 10.23.1.10 | RHEL 9.3 | US-East (nyc1) | 15 | 2 | 5 | 2026-06-28 |
| FW-PROD-01 | 10.23.0.1 | PAN-OS 11.1 | US-East (nyc1) | 12 | 0 | 3 | 2026-06-27 |
| CVE | Asset | Justification | Accepted By | Accepted At | Expires | Days Left |
|---|
No data imported yet. Upload vulnerability scan and device export CSV files above.
Loading KEV catalog...
Plugin ID, CVE, CVSS, Risk, Host, Protocol, Port, Name, Synopsis, Description, Solution, See Also, Plugin Output
Name, OperatingSystem, ADSite, ADOU, LastLogonUser, Manufacturer, Model, SystemRole, IsVirtual, Processor, Memory, DiskSpace
| User | Username | Role | Teams | Last Login | |
|---|---|---|---|---|---|
DA David Admin |
david | Admin | All | 2026-06-28 07:12 | |
JS Jane Smith |
jsmith | User | Infrastructure, Platform Engineering | 2026-06-28 06:55 | |
MW Mike Wilson |
mwilson | User | Security Operations | 2026-06-27 14:30 | |
RK Rachel Kim |
rkim | User | Application Services | 2026-06-27 10:18 |
OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET env vars to enable OIDC.
Non-KEV vulnerability findings are assigned a severity-based due date measured from first detection (firstSeen). KEV-matched findings use the CISA BOD 22-01 federal deadline.
check_team_access. Team detail now shows period-over-period deltas.fixed_at transition timestamp. OS backfill from endpoint inventory.executemany. Asset tags junction table. Solutions view and change-request draft assembler.