< ciso
brief />
Tag Banner

All news with #cisa kev tag

189 articles

CISA Adds Six Exploited Flaws, Urges Immediate Patching

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, urging prompt patching by government agencies and critical infrastructure. Two high-severity flaws—CVE-2026-8452 in Citrix NetScaler and CVE-2019-1068 in Microsoft SQL Server—carry CVSS scores of 8.8 and require immediate attention. Citrix has published updates to address the NetScaler memory overflow, while the SQL Server RCE remains actively exploited despite a seven-year-old patch. CISA set accelerated patch deadlines for the critical and other listed flaws.
read more →

CISA Adds Six Actively Exploited Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity issue in Citrix NetScaler ADC and NetScaler Gateway with evidence of active exploitation. The list includes flaws affecting Microsoft SQL Server, the Linux Kernel, Red Hat components, Ajax.NET Professional, and Citrix, with CISA issuing remediation deadlines for federal agencies. Security firms reported web shells and discovery activity tied to attempts exploiting the Citrix flaw, and telemetry has identified multiple attacker IPs worldwide. CISA also published a vulnerability review highlighting injection and memory-safety weaknesses as frequent root causes of exploitation.
read more →

CISA Adds Critical Oracle WebLogic Flaw to KEV

🔒 CISA has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw allows unauthenticated HTTP access to create, modify, or delete critical data and potentially gain full access to affected instances. Oracle released patches in January, but reports from GreyNoise and CloudSEK indicate ongoing exploitation activity. Federal agencies must remediate under BOD 26-04 by August 27, 2026.
read more →

CISA orders urgent Zimbra patching for active exploit

🔔 The Cybersecurity and Infrastructure Security Agency (CISA) directed U.S. federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite flaw (CVE-2026-73570) within three days after CERT Polska reported in-the-wild attacks. The flaw, fixed in Zimbra 10.1.20 released July 20, permits unauthenticated remote code execution via a command injection in the SNMP notification component when enabled. Administrators are urged to review recent logs for indicators such as unexpected service restarts and newly created files under zimbra-owned webapps and /tmp directories.
read more →

CISA orders federal patching for TrueConf flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more →

CISA Alerts: Active Exploitation of MLflow SSRF Bug

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical MLflow vulnerability (CVE-2026-64849) that enables a DNS-rebinding SSRF bypass in MLflow's outbound webhook delivery. The flaw, patched in MLflow 3.15.0, allows unauthenticated attackers to make the tracking server issue requests to internal and cloud-metadata endpoints and read responses, risking theft of cloud credentials. CISA added the issue to its KEV catalog and ordered federal agencies to remediate under BOD 26-04, urging all defenders to prioritize patching.
read more →

CISA: Windows Task Host Flaw Now Exploited by Ransomware

🔒 CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more →

CISA Adds Actively Exploited Critical Ray Flaw

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more →

Critical LoadMaster Command Injection Added to CISA KEV

🔒 CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaw, rooted in improper input handling in an escape_quotes() function, allows unauthenticated attackers to execute arbitrary commands on affected appliances. Agencies are urged to apply patches immediately under BOD 26-04 to mitigate ongoing attacks.
read more →

CISA warns of active exploits in three products

🚨 The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. The most severe issue, tracked as CVE-2026-9198, impacts Langflow and permits unauthenticated remote code execution via chained API endpoints. Vendors have released patches and a hotfix, but incomplete fixes and public proof-of-concept exploits have enabled ongoing attacks. CISA added all three flaws to its Known Exploited Vulnerabilities catalog and urged immediate remediation.
read more →

CISA Adds Langflow, Tomcat and N‑able Flaws to KEV

🛡️ CISA on August 5, 2026, added three actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a critical Langflow RCE (CVE-2026-9198) and an Apache Tomcat encryption bypass (CVE-2026-34486). The advisory also includes an N-able N-central authentication bypass (CVE-2026-18556) and a related incomplete fix tracked as CVE-2026-18577. Agencies must apply available patches and mitigations promptly to prevent ongoing exploitation.
read more →

Cisco FMC Zero‑Day Added to CISA KEV Catalog

🔒 CISA has added a newly disclosed zero‑day affecting Cisco Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated remote actor to log in using a static low‑privilege account and access sensitive data; Cisco warns the risk increases if the management interface is internet‑exposed. Hotfixes are available for multiple FMC versions and Cisco published an IoC check for "/var/tmp/license.tmp" to help detect compromise.
read more →

Check Point patches SmartConsole zero-day exploit

🔒 Check Point has released a patch for an actively exploited SmartConsole zero-day (CVE-2026-16232) that permits unauthenticated attackers to obtain an application login token and authenticate with administrator privileges. Successful exploitation requires the Management Server to be reachable from the Internet and Trusted Clients not being restricted, allowing attackers to alter security configurations and policies. The vendor urged affected customers to apply updates and recommended mitigations, while CISA has added the flaw to its known exploited vulnerabilities catalog and ordered federal agencies to patch by July 25.
read more →

CISA urges immediate patching of Fortinet FortiSandbox

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by July 19. Both flaws are OS command injection bugs with CVSS scores of 9.1 and have documented in-the-wild exploitation. Fortinet released fixes in FortiSandbox versions 4.4.9 and 5.0.6; CISA advised discontinuing cloud services where mitigations are unavailable.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →

SonicWall SMA 1000 Zero‑Days Prompt Urgent Patches

🛡️ SonicWall warned of active exploitation of two zero‑day vulnerabilities affecting Secure Mobile Access (SMA) 1000 series appliances, including an SSRF that scores 10.0 and a post‑auth code injection allowing command execution. Patches are available in platform hotfix builds 12.4.3‑03453, 12.5.0‑02835 and later; customers are urged to apply fixes and perform forensic checks for specific IoCs. CISA added both flaws to its KEV catalog and set a July 17, 2026 deadline for federal agencies.
read more →

CISA warns of exploited RCE in Joomla extensions

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting arbitrary file upload vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution. The agency designated these flaws as maximum priority and ordered federal agencies to apply updates or mitigations within three days. Vendors released fixes in iCagenda 4.0.8/3.9.15 and Balbooa Forms 2.4.1 after automated and zero-day exploitation was observed. Administrators should check installations and apply the available patches immediately.
read more →

CISA directs federal patch for ColdFusion zero-day

🔒 The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch an actively exploited, maximum-severity vulnerability in Adobe ColdFusion (CVE-2026-48282) by Friday. Adobe published fixes for affected ColdFusion versions last week and urged administrators to install updates immediately. The flaw enables unauthenticated remote code execution in low-complexity attacks and has been observed in the wild soon after disclosure. CISA added the issue to its KEV catalog and invoked BOD 26-04 to enforce remediation timelines for FCEB agencies.
read more →

CISA Adds Four Newly Exploited Vulnerabilities

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaws include critical Adobe ColdFusion path traversal (CVE-2026-48282), Joomlack Page Builder improper access control (CVE-2026-56290), Langflow authorization bypass (CVE-2026-55255), and JoomShaper SP Page Builder unrestricted file upload (CVE-2026-48908). Exploitation observed ranged from immediate post-disclosure attacks to targeted campaigns stealing credentials and deploying web shells. Agencies are urged to apply patches by July 10, 2026.
read more →