Tag

#CISA KEV

25 stories taggedCISA KEV.

Photoreal news-editorial shot of a dimly lit server rack in an enterprise data center, amber status LEDs glowing on rack-mounted servers, faint blue ambient lig
Vulnerabilities

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC

CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened server room corridor with a single rack door ajar, cool blue emergency lighting spilling across p
Ransomware

Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws

CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug that has been patched since mid-July. Roughly 380 appliances are still sitting online.

3 min read
Photoreal editorial shot of a dimly lit server rack with amber warning LEDs reflecting off polished metal, rows of patch cables in soft focus, cool blue ambient
Vulnerabilities

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts

A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

4 min read
A digital illustration of a computer screen displaying Notepad++ with highlighted XML code, indicating a security vulnerability
Vulnerabilities

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter

Security teams are buried in alerts while attackers move faster than ever. The real problem is not a shortage of warnings. It is knowing which ones actually matter before criminals act on them.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of dark server racks, one rack visibly powered down with cables hanging loose, cool bl
Ransomware

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward

A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Arista rushes fix for VeloCloud flaw already being used in attacks

A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

4 min read
A visual representation of a digital storm hitting a Drupal logo, symbolizing a security vulnerability
Vulnerabilities

CISA orders three-day fix as Clop hits PTC Windchill flaw

A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

4 min read
A server rack in a dimly lit data center, glowing amber and blue indicator lights reflecting off brushed-metal chassis surfaces, shallow depth of field on the f
Vulnerabilities

Hackers Are Actively Exploiting a Flaw in Check Point Security Software

A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

3 min read
Photoreal editorial shot of a dimly lit server room with a rack-mounted enterprise firewall appliance glowing red on its status LEDs, blue network cables tangle
Ransomware

Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw

Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.

3 min read
Photoreal news-editorial shot of a rack-mounted network security appliance in a dim server room, blue and amber status LEDs glowing, ethernet cables neatly bund
Vulnerabilities

SonicWall says two SMA1000 flaws are being used in live attacks

One bug scores a perfect 10 on the severity scale. Federal agencies have until July 17, 2026 to patch or pull the plug.

3 min read
Vulnerabilities

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited

The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

2 min read
Vulnerabilities

Active Exploitation Hits PTC Windchill as Attackers Drop Web Shells on PLM Systems

A critical deserialization flaw in software used by Boeing, Lockheed Martin, and BMW is drawing threat actors toward some of the most sensitive intellectual property in global manufacturing.

2 min read
Vulnerabilities

PTC Windchill RCE Lands on CISA's KEV After Web Shells Show Up in the Wild

A pre-auth code execution bug in PTC's PLM stack is being actively exploited. If you run Windchill or FlexPLM, the patch clock started a while ago.

2 min read
Vulnerabilities

CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug

CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch — but if it's already being hit in the wild, that runway looks generous.

2 min read
Vulnerabilities

CISA Flags Joomla Content Editor Bug as Actively Exploited; CVSS 10.0

CVE-2026-48907 in Widget Factory's JCE extension hands attackers arbitrary file actions on unpatched Joomla sites. Federal agencies get the standard three weeks.

2 min read
© 2026 Threat Vectr