The September 17 Cyber Centre alert AL26-021 describes CVE-2026-20192 as an improper access-control issue affecting Cisco ISE and ISE-PIC. It appears alongside two other identifiers in the same alert.
A shared advisory is not evidence that all three issues have the same cause, prerequisites, or activity history. I keep a separate entry for each identifier, then record which statements the source explicitly makes about it.
For this entry, the source label is AL26-021 and the weakness classification is CWE-284. Any local inventory note should include the complete release and patch identifier rather than just the product name.
How are you organizing notes when one vendor bulletin covers several different findings?
One row per identifier, with a separate source column. I also keep “not stated” as a valid value. Filling a gap with an assumption makes a table look complete while making it less reliable.
The September 17 Cyber Centre alert AL26-021 describes CVE-2026-20192 as an improper access-control issue affecting Cisco ISE and ISE-PIC. It appears alongside two other identifiers in the same alert.
A shared advisory is not evidence that all three issues have the same cause, prerequisites, or activity history. I keep a separate entry for each identifier, then record which statements the source explicitly makes about it.
For this entry, the source label is AL26-021 and the weakness classification is CWE-284. Any local inventory note should include the complete release and patch identifier rather than just the product name.
How are you organizing notes when one vendor bulletin covers several different findings?