
Can an Indirect Vulnerability Still Be High Risk?
CVE-2026-20045 does not directly affect most devices and products, but its potential impact depends entirely on how affected systems connect to them. CISA added CVE-2026-20045
" " indicates required fields

CVE-2026-20045 does not directly affect most devices and products, but its potential impact depends entirely on how affected systems connect to them. CISA added CVE-2026-20045

Medical device manufacturers are no longer struggling to find vulnerabilities. They are struggling to decide which ones matter. As SBOM adoption has expanded, security and
CRO
C2A Security
VP and GM, Medical Technology
C2A Security
Ken Zalevsky brings over 20 years of medical device cybersecurity experience to his role at C2A Security, where he serves as VP and GM, Medical Technology, following the acquisition of Vigilant Ops in October 2025. A former Bayer executive, Ken founded Vigilant Ops in 2019 after witnessing the consequences of inadequate technical preparation in the healthcare industry. He is an active contributor to CISA’s SBOM working groups and a frequent speaker on software supply chain security. Ken’s mission: transform SBOM from a compliance checkbox into operational intelligence that keeps patients safe while streamlining regulatory processes.