Tag

#KEV

16 stories taggedKEV.

Illustration: a government operations desk at night, glowing amber monitor showing abstract vulnerability catalogue rows
Vulnerabilities

CISA Gives Federal Agencies Three Days to Patch Two Zammad Flaws Being Exploited Now

Two critical bugs in the Zammad helpdesk platform can be chained for root-level takeover. CISA added both to the Known Exploited Vulnerabilities catalogue on 2 October 2026, with a patch deadline of 5 October.

3 min read
Federal cybersecurity operations center with urgent alert banners across multiple screens displaying NetScaler vulnerability information, patch deployment timel
Vulnerabilities

CISA Warns of Active Attacks on Critical NetScaler Flaw

Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

3 min read
A network operations center with multiple security monitoring screens displaying alerts and warnings, three different product logos or interface elements visibl
Vulnerabilities

CISA flags five actively exploited flaws in Artifactory, ScreenConnect and MikroTik gear

The U.S. cyber agency says criminals are already breaking into systems through bugs in three widely used products, and federal agencies must patch fast.

3 min read
A network operations center displaying security alerts and vulnerability notifications on multiple screens, with CISA threat bulletin information visible on the
Vulnerabilities

CISA flags seven actively exploited flaws, including two in SonicWall SMA1000 boxes

The US cyber agency's Known Exploited Vulnerabilities catalog picks up bugs in Sangoma, JFrog, LiteLLM, Kestra, Starlette and a pair in SonicWall's remote access appliances.

4 min read
A government office building exterior with alert notifications and warning symbols overlaid, representing federal agencies receiving urgent patching directives
Vulnerabilities

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused

Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

3 min read
A server room filled with blinking network equipment and cooling systems, with red warning lights illuminating the hardware, suggesting active threat detection
Vulnerabilities

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

3 min read
A server room with rows of blinking rack-mounted equipment, one unit highlighted with a red warning indicator among dozens of others still operating normally, d
Vulnerabilities

Ransomware crews are now breaking into SharePoint servers through a May flaw

CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

4 min read
A CISA alert notification displayed on a government cybersecurity operations center screen, with actively exploited vulnerabilities being added to the official
Vulnerabilities

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List

A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

3 min read
IT service provider office with technicians managing remote monitoring dashboards, security alerts and vulnerability notifications visible on screens, urgent re
Vulnerabilities

CISA flags N-able N-central bug as actively exploited, orders federal fix

The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

3 min read
Illustration: a dimly lit server rack in a data centre, with amber warning lights glowing on network switches
Vulnerabilities

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild

CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

3 min read
A government security forum presentation stage with a South Korean cybersecurity executive addressing an audience of corporate security leaders, displaying brea
AI Security

AI Is Cutting the Time to Find a Hack From Weeks to Hours. Here Is What Security Teams Should Do About It.

South Korean hacker-turned-CEO Park Chan-am told a government security forum that artificial intelligence has shattered old assumptions about how fast criminals break into corporate systems, and that most organisations aren't ready.

4 min read
A dimly lit server room with rows of dark racks, one panel glowing red with warning indicator lights, thin blue fibre-optic cables running along the ceiling, sh
Vulnerabilities

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited

CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both carrying the maximum severity score.

3 min read
Illustration: a darkened server rack in a data centre, blue and amber status lights glowing
Vulnerabilities

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked

CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

4 min read
Illustration: a dimly lit server room with rows of dark rack-mounted servers
Vulnerabilities

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow

The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

3 min read
Illustration: A darkened server room with a single illuminated rack
Vulnerabilities

CISA Flags Actively Exploited SimpleHelp Flaw, Orders Federal Agencies to Patch Fast

A newly listed authentication bypass in SimpleHelp remote-support software is being used in real attacks, and federal agencies now face a hard deadline to fix it.

3 min read
© 2026 Threat Vectr