cisa cybersecurity mcp server MCP Resources
cisa cybersecurity mcp server offers 60 resources. A resource is data the server exposes for a client to attach as context — a file, a page, an API response — rather than an action. Each has its own page, per client.
-
CVE-2026-71362 — Adobe Commerce and Magento Incorrect Authorization Vul… -
CVE-2026-5430 — WSO2 Multiple Products Path Traversal Vulnerability -
CVE-2026-94127 — F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability -
CVE-2026-93952 — Arista VeloCloud Orchestrator Improper Input Validatio… -
CVE-2026-93616 — Check Point Multiple Products Path Traversal Vulnerabi… -
CVE-2026-85102 — Check Point Multiple Products Improper Certificate Val… -
CVE-2026-7273 — Zyxel GS1900 Series Switches Stack-Based Buffer Overflo… -
CVE-2026-53266 — Linux Kernel Out-of-Bounds Write Vulnerability -
CVE-2025-39964 — Linux Kernel Race Condition Vulnerability -
CVE-2025-39682 — Linux Kernel Improper Check for Unusual or Exceptional… -
CVE-2026-87886 — Acronis Backup Incorrect Default Permissions Vulnerabi… -
CVE-2026-76460 — Cisco Identity Services Engine Incorrect Use of Privil… -
CVE-2026-58704 — Google Pixel Improper Authorization Vulnerability -
CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability -
CVE-2026-85706 — GitLab Community Edition and Enterprise Edition Path T… -
CVE-2026-84869 — ConnectWise ScreenConnect Improper Privilege Managemen… -
CVE-2026-42018 — JFrog Artifactory Improper Authentication Vulnerability -
CVE-2026-42016 — JFrog Artifactory Incorrect Authorization Vulnerability -
CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument … -
CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical … -
CVE-2026-87491 — Google Chromium V8 Out of Bounds Write Vulnerability -
CVE-2026-20079 — Cisco Firewall Management Center Authentication Bypass… -
CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Altern… -
CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow … -
CVE-2026-86218 — N-able N-central Static Code Injection Vulnerability -
CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerabi… -
CVE-2026-81963 — Microsoft Windows Link Following Vulnerability -
CVE-2026-75650 — Adobe Commerce and Magento Improper Neutralization of … -
CVE-2026-85046 — Google Chromium V8 Type Confusion Vulnerability -
CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability -
ICSA-26-265-01 — lwIP TCP/IP Stack MQTT Client Application -
ICSA-26-265-02 — lwIP (Lightweight IP) -
ICSA-26-265-03 — Siemens Siveillance Control -
ICSA-26-265-04 — Siemens SIPLUS and SIMATIC Products -
ICSA-26-265-05 — Siemens Desigo CC family -
ICSA-26-265-06 — Siemens Industrial Edge Management -
ICSA-26-265-07 — Siemens SIMOVE Fleetmanager and SIPLANT -
ICSA-26-265-08 — Siemens WTV676 and WTV776 -
ICSA-26-265-09 — OpenPLC Runtime v3 -
ICSA-26-260-07 — Schneider Electric PowerChute Serial Shutdown -
ICSA-26-260-06 — ABB Ability Edgenius -
ICSA-26-260-05 — Schneider Electric NetBotz 5 750/755 -
ICSA-26-260-04 — Schneider Electric Modicon M340 Controller and Communi… -
ICSA-26-260-03 — Hitachi Energy FACTS Control Platform (FCP) -
ICSA-26-260-02 — Mitsubishi Electric GX Works3 and Motion Control Setti… -
ICSA-26-260-01 — Bransys ELD -
ICSA-26-211-07 — Mitsubishi Electric CC-Link IE TSN Communication Proto… -
ICSA-26-258-08 — CareCam CM2507 -
ICSA-26-258-07 — Siemens Teamcenter -
ICSA-26-258-06 — Siemens Mendix SAML -
ICSA-26-258-05 — Siemens Reyrolle 7SR5 -
ICSA-26-258-04 — Schneider Electric SCADAPack x70 Products -
ICSA-26-258-03 — mySCADA myPRO Manager -
ICSA-26-258-02 — Wärtsilä FOS-Onboard -
ICSA-26-258-01 — Digital Watchdog VMAX DVR and NVR Product Lineups -
ICSA-26-197-05 — Siemens SICAM 8 -
ICSA-26-174-03 — Siemens Products using OpenSSL -
ICSA-25-226-22 — Siemens Web Installer -
ICSA-25-226-05 — Siemens IAM Client -
ICSA-25-135-18 — Siemens SCALANCE LPE9403
Read from the server itself, by connecting to it and calling resources/list on 24 September 2026.
A listing does not declare its resources, so asking is the only way to know them, and this
is what the server actually offers rather than what its listing claims. Names only are
stored; connect the server for each resource's type and contents.