<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>vuln.management</title><description>Posts, advisories, playbooks, and memes for modern vulnerability management.</description><link>https://vuln.management/</link><language>en-us</language><item><title>A field guide to agentic vulnerability management (with an actual off switch)</title><link>https://vuln.management/posts/agentic-vulnerability-management-field-guide/</link><guid isPermaLink="true">https://vuln.management/posts/agentic-vulnerability-management-field-guide/</guid><description>A practical operating model for introducing agents without confusing automation, authority, and accountability.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>Agents</category><category>Operating model</category></item><item><title>Finding vulnerabilities is getting cheaper. The backlog has noticed.</title><link>https://vuln.management/posts/finding-is-cheap/</link><guid isPermaLink="true">https://vuln.management/posts/finding-is-cheap/</guid><description>AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>AI &amp; agents</category><category>Prioritization</category></item><item><title>The vulnerability ticket is an interface, not a filing cabinet</title><link>https://vuln.management/posts/vulnerability-ticket-interface/</link><guid isPermaLink="true">https://vuln.management/posts/vulnerability-ticket-interface/</guid><description>A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>Workflow</category><category>Remediation</category></item><item><title>GHSA-vwf4-m7j8-wcjf: Metabase says its critical zero-day was actively exploited</title><link>https://vuln.management/advisories/ghsa-vwf4-m7j8-wcjf-metabase/</link><guid isPermaLink="true">https://vuln.management/advisories/ghsa-vwf4-m7j8-wcjf-metabase/</guid><description>An unauthenticated SQL-injection path can lead to Metabase administrator access, exposed database credentials, and data theft.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>Advisory</category><category>Metabase</category><category>Active exploitation</category></item><item><title>CVE-2026-63077: TeamCity unauthenticated RCE is in CISA KEV</title><link>https://vuln.management/advisories/cve-2026-63077-jetbrains-teamcity/</link><guid isPermaLink="true">https://vuln.management/advisories/cve-2026-63077-jetbrains-teamcity/</guid><description>CISA reports that unsafe deserialization in the TeamCity agent polling protocol can permit unauthenticated remote code execution.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>Advisory</category><category>JetBrains</category><category>Known exploited</category></item><item><title>CVE-2026-9198: Unauthenticated Langflow code injection is in CISA KEV</title><link>https://vuln.management/advisories/cve-2026-9198-ibm-langflow/</link><guid isPermaLink="true">https://vuln.management/advisories/cve-2026-9198-ibm-langflow/</guid><description>CISA says default Langflow deployments may permit unauthenticated attackers to achieve full remote code execution.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>Advisory</category><category>IBM</category><category>Known exploited</category></item><item><title>CVE-2026-8037: Progress LoadMaster command injection is in CISA KEV</title><link>https://vuln.management/advisories/cve-2026-8037-progress-loadmaster/</link><guid isPermaLink="true">https://vuln.management/advisories/cve-2026-8037-progress-loadmaster/</guid><description>CISA says an unauthenticated attacker can execute arbitrary commands through unsanitized input in multiple LoadMaster command endpoints.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>Advisory</category><category>Progress</category><category>Known exploited</category></item></channel></rss>