#CISA KEV
36 stories taggedCISA KEV.

Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch
A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

Langflow's Built-In Testing Tool Has No Password and Attackers Are Using It Right Now
Three critical flaws in the popular AI workflow builder let attackers run any code they like on your server, as root, without logging in. CISA ordered federal agencies to patch by May 26. Attackers are not waiting.

ShinyHunters Claims a Second PeopleSoft Zero-Day, and Oracle Has Said Nothing
A known criminal group says it used an unpatched Oracle flaw to break into FBI systems. The first PeopleSoft vulnerability is already being actively exploited. A possible second one has no patch, no CVE, and no vendor comment.

Citrix NetScaler Zero-Day Is Knocking Login Systems Offline
A memory flaw in NetScaler ADC and Gateway, now exploited in the wild, can crash the gateways many companies rely on for single sign-on. US federal agencies have three days to patch.

Fortinet FortiMail Has a Critical Zero-Day Being Exploited and No Patch Yet
A vulnerability scored 9.8 out of 10 in Fortinet FortiMail lets attackers write files to affected servers without logging in. Fixes are not out yet. US federal agencies had until 4 October 2026 to apply workarounds.

Cisco SD-WAN flaw gives attackers admin keys, and someone is already using it
CISA gave federal agencies three days to patch CVE-2026-76504 after evidence the authentication bypass is being exploited in the wild.

Zimbra mail server flaw exploited in the wild, Microsoft warns after weeks of quiet attacks
Microsoft Threat Intelligence says attackers used a specially crafted email to hijack Zimbra Collaboration Suite mail servers, drop web shells and steal mailbox data, before the flaw was patched.

Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System
A critical flaw in Oracle's PeopleSoft business software is under active attack, with federal agencies given days to patch.

CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited
Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

CISA gives federal agencies three days to patch a Zyxel switch bug already being used in attacks
CVE-2026-7273 lets anyone on the local network hijack GS1900 switches with a single crafted web request. Federal deadline: 24 September 2026.

Check Point patches critical login flaw that hands attackers root on firewall management servers
CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them
Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

Cisco firewall manager flaw rated 10 out of 10 is under active attack
A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.