#CISA KEV
36 stories taggedCISA KEV · page 2 of 3.

Ransomware Crews Now Hitting Unpatched WatchGuard Firewalls, CISA Warns
A critical flaw in WatchGuard Firebox firewalls, patched in December, is now being used in ransomware attacks. Close to 9,000 devices remain exposed online.

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside
A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory
A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

Chinese-Speaking Hackers Hit Philippine Nuclear Research Agency Through ownCloud Bug
CISA has flagged a critical flaw in the file-sharing tool ownCloud as actively exploited, after attackers used it to steal data from a nuclear research body in the Philippines.

8,300 Gitea servers still exposed to a code injection bug attackers are already using
A flaw in Gitea's diffpatch endpoint lets low-privilege users run shell commands on the server. CISA gave federal agencies three days to patch. Most operators haven't.

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers
The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws
CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug patched in mid-July. Around 380 appliances are still sitting online.

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts
A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem isn't a shortage of warnings. It's knowing which ones actually matter before criminals act on them.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

Arista rushes fix for VeloCloud flaw already being used in attacks
A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

CISA orders three-day fix as Clop hits PTC Windchill flaw
A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw
Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.