Tag

#CISA KEV

36 stories taggedCISA KEV · page 2 of 3.

A network operations center displaying thousands of WatchGuard firewall devices on a map, critical unpatched devices highlighted in red, ransomware attack alert
Vulnerabilities

Ransomware Crews Now Hitting Unpatched WatchGuard Firewalls, CISA Warns

A critical flaw in WatchGuard Firebox firewalls, patched in December, is now being used in ransomware attacks. Close to 9,000 devices remain exposed online.

3 min read
Illustration: A dimly lit enterprise server room at night
Vulnerabilities

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside

A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

3 min read
A software deployment dashboard displaying administrator access controls being progressively elevated, authentication logs showing unauthorized privilege escala
Vulnerabilities

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory

A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

3 min read
A research facility's interior showing server equipment and scientific instrumentation, with cybersecurity warning symbols or breach indicators subtly visible i
Vulnerabilities

Chinese-Speaking Hackers Hit Philippine Nuclear Research Agency Through ownCloud Bug

CISA has flagged a critical flaw in the file-sharing tool ownCloud as actively exploited, after attackers used it to steal data from a nuclear research body in the Philippines.

3 min read
A software development environment displaying Git repository management interface with code diff and patch utilities visible, warning indicators appearing in th
Vulnerabilities

8,300 Gitea servers still exposed to a code injection bug attackers are already using

A flaw in Gitea's diffpatch endpoint lets low-privilege users run shell commands on the server. CISA gave federal agencies three days to patch. Most operators haven't.

3 min read
A corporate server room with Oracle WebLogic servers and associated hardware, with critical alert notifications flashing on monitoring dashboards, showing activ
Vulnerabilities

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers

The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

3 min read
A Windows system tray showing Task Host process with escalation arrows climbing to SYSTEM-level privileges, with ransomware operators silhouetted in the backgro
Vulnerabilities

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC

CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

3 min read
A network rack in a corporate server room showing a SonicWall appliance with its indicator lights glowing, surrounded by layers of other security hardware, cabl
Ransomware

Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws

CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug patched in mid-July. Around 380 appliances are still sitting online.

3 min read
A network load balancer device with warning indicator lights illuminated, surrounded by cascading alert notifications on nearby monitors
Vulnerabilities

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts

A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

3 min read
A security operations center with multiple monitors displaying vulnerability alerts and threat indicators, operators with overwhelmed expressions working throug
Vulnerabilities

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter

Security teams are buried in alerts while attackers move faster than ever. The real problem isn't a shortage of warnings. It's knowing which ones actually matter before criminals act on them.

3 min read
A corporate network diagram with SonicWall device icons highlighted in red, connected to multiple compromised systems across a geographical map, with phone hand
Ransomware

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward

A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

3 min read
Network infrastructure diagram on a monitor displaying VeloCloud Orchestrator nodes under attack, with active exploitation indicators spreading across the syste
Vulnerabilities

Arista rushes fix for VeloCloud flaw already being used in attacks

A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

3 min read
A PTC Windchill product design interface on a monitor with a warning banner overlaid, surrounded by regulatory documents from US and German agencies with three-
Vulnerabilities

CISA orders three-day fix as Clop hits PTC Windchill flaw

A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

4 min read
A Check Point network management console showing unauthorized administrator login activity, security logs displaying unrestricted access granted without credent
Vulnerabilities

Hackers Are Actively Exploiting a Flaw in Check Point Security Software

A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

3 min read
Illustration: a dimly lit server room with a rack-mounted enterprise firewall appliance glowing red on its status LEDs
Ransomware

Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw

Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.

3 min read
© 2026 Threat Vectr