Tag: kev
-
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/
-
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/
-
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/netscaler-adc-gateway-cve-2026-8452/
-
CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability
Tags: cisa, cve, cyber, cybersecurity, exploit, infrastructure, kev, microsoft, rce, remote-code-execution, service, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server…
-
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, remote-code-execution, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2019-1068 – A remote code execution vulnerability in First seen on thehackernews.com Jump…
-
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, open-source, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for…
-
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability…
-
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Tags: access, cve, cybersecurity, data, exploit, flaw, infrastructure, kev, network, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to First seen on…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
First seen on scworld.com Jump to article: www.scworld.com/news/trueconf-flaws-enabling-attacks-on-meeting-participants-added-to-kev-catalog
-
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors…
-
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueConf. Organizations can deploy it on their…
-
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a…
-
CISA Warns Microsoft Internet Key Exchange RCE Flaw Is Actively Exploited
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, Internet, kev, microsoft, rce, remote-code-execution, service, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, tracked as CVE-2026-33824, is currently being actively exploited. The issue is classified as a double-free vulnerability, which means it affects the memory management of Microsoft…
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Tags: apple, authentication, cve, cybersecurity, exploit, flaw, infrastructure, kev, macOS, microsoft, vcenter, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild.The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an…
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Tags: apple, authentication, cve, cybersecurity, exploit, flaw, infrastructure, kev, macOS, microsoft, vcenter, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild.The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an…
-
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Tags: apple, cisa, cve, cybersecurity, exploit, flaw, infrastructure, Internet, kev, macOS, microsoft, remote-code-execution, service, vcenter, vmware, vulnerability, windowsU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution…
-
CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, hacker, infrastructure, kev, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, tracked as CVE-2026-59310, is a path traversal flaw that enables arbitrary code execution in affected vCenter deployments. VMware vCenter Path Traversal Flaw CVE-2026-59310 impacts the VMware vCenter Syslog Server…
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray,…
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Tags: ai, cisa, computing, cybersecurity, exploit, flaw, framework, github, infrastructure, intelligence, kev, open-source, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than First seen…
-
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, ransomware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue found in the Workplace interface of SonicWall SMA1000 appliances. It has…
-
CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances, posing a significant risk to organizations that expose LoadMaster…
-
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
-
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress”¯Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary First seen on…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity…
-
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
Tags: cisa, cve, cyber, cybersecurity, data-breach, exploit, flaw, infrastructure, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This flaw allows unauthenticated remote code execution (RCE) on vulnerable TeamCity On-Premises servers exposed via HTTP or HTTPS. CISA Issues on TeamCity RCE…

