Tag: kev
-
CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
CISA added CVE-2026-87886 to its KEV catalog after confirmed exploitation of an Acronis Backup flaw affecting Linux hosting environments. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-acronis-backup-flaw-exploited/
-
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch. The post CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-pixel-modem-zero-day-cve-2026-58704/
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cisco, cve, cybersecurity, email, exploit, flaw, infrastructure, kev, vulnerability, zero-dayU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week;…
-
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and…
-
CISA KEV Alert: Cisco, Citrix, and Fortinet Vulnerabilities Under Active Exploitation
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cisa-kev-alert-cisco-citrix-and-fortinet-vulnerabilities-under-active-exploitation
-
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization First seen on thehackernews.com…
-
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, gitlab, infrastructure, Internet, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability…
-
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277…
-
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cisco, citrix, cve, cybersecurity, exploit, flaw, fortinet, google, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure…
-
Daily OT Security News: September 10, 2026
Cisco FMC Flaw Added to CISA’s Known Exploited Vulnerabilities Catalog SecurityWeek reported that Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center that can let a remote unauthenticated attacker execute malicious… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-10-2026/
-
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Tags: authentication, cisa, cisco, citrix, cve, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication First seen…
-
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, vulnerability, windowsU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a…
-
CISA Adds 7 Exploited Flaws as Attackers Target AI Infrastructure
CISA added seven exploited flaws to its KEV catalog, including LiteLLM, Kestra, Starlette, and SonicWall vulnerabilities under active attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-cisa-exploited-ai-flaws/
-
CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks
Tags: access, attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, mobile, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances. CISA Warns SonicWall SMA1000 Flaws CISA…
-
CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks
Tags: access, attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, mobile, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances. CISA Warns SonicWall SMA1000 Flaws CISA…
-
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs.The vulnerabilities are as follows – CVE-2026-83548 (CVSS score: 10.0) – A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated First seen…
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/
-
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of First…
-
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who…
-
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, microsoft, sql, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let…
-
CVE vs CWE vs CAPEC vs MITRE ATTCK: What They Are and Why Your Content Needs Them
CVE, CWE, CAPEC, ATT&CK, CVSS, KEV, ATLAS. The security taxonomy acronyms get used interchangeably and they should not be. Here is what each one actually does, how they chain together, and why they matter more for your content strategy than most security marketers realize. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cve-vs-cwe-vs-capec-vs-mitre-attck-what-they-are-and-why-your-content-needs-them/
-
CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability
Tags: cisa, citrix, cve, cyber, cybersecurity, exploit, infrastructure, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. This vulnerability was added on August 26, 2026, and federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026. Citrix…

