Tag

#KEV

22 stories taggedKEV.

Full-frame edge-to-edge photoreal editorial shot of a server rack with a single network appliance highlighted by red status LEDs, blurred data center aisle in b
Vulnerabilities

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused

Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

3 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

CISA Orders Urgent Fixes for Four Actively Exploited Flaws in Windows, VMware, and macOS

Four security holes, all being actively abused by real attackers right now, need patches immediately. Two hit Microsoft, one VMware, one Apple.

4 min read
A dimly lit server room with rows of dark racks, one panel glowing red with warning indicator lights, thin blue fibre-optic cables running along the ceiling, sh
Vulnerabilities

CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

3 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

Ransomware crews are now breaking into SharePoint servers through a May flaw

CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

4 min read
Aerial 16:9 editorial photograph of a multi-lane American interstate highway at dusk, large digital message signs mounted on overhead gantries displaying amber
Vulnerabilities

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List

A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Vulnerabilities

CISA flags N-able N-central bug as actively exploited, orders federal fix

The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild

CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

4 min read
Full-frame photoreal editorial image of a dark modern security operations centre at night, rows of monitors glowing with abstract identity graphs and network no
AI Security

AI Is Cutting the Time to Find a Hack From Weeks to Hours. Here Is What Security Teams Should Do About It.

South Korean hacker-turned-CEO Park Chan-am told a government security forum that artificial intelligence has shattered old assumptions about how fast criminals can break into corporate systems, and that most organisations are not ready.

4 min read
Photoreal editorial shot of a dimly lit server rack with a single glowing amber warning light, faint reflections of code on the metal, shallow depth of field, c
Vulnerabilities

CISA flags active attacks on two Joomla add-ons that let hackers take over websites

Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

3 min read
A dimly lit server room with rows of dark racks, one panel glowing red with warning indicator lights, thin blue fibre-optic cables running along the ceiling, sh
Vulnerabilities

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited

CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both scored a perfect 10 on the severity scale.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened server rack in a data centre, blue and amber status lights glowing, one drawer pulled sligh
Vulnerabilities

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked

CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with rows of dark rack-mounted servers, blue and amber status LEDs reflecting
Vulnerabilities

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow

The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Vulnerabilities

CISA Flags Actively Exploited SimpleHelp Flaw, Orders Federal Agencies to Patch Fast

A newly listed authentication bypass in SimpleHelp remote-support software is being used in real attacks, and federal agencies now face a hard deadline to fix it.

3 min read
Vulnerabilities

Splunk Enterprise RCE Flaw Under Active Exploitation, CISA Gives Feds 72 Hours

CVE-2026-20253 allows unauthenticated remote code execution in Splunk Enterprise. Attackers didn't wait long.

2 min read
Vulnerabilities

The Exposures Defenders Will Be Cleaning Up in 2026

From memory-leak bugs like MongoBleed to forgotten admin panels, the attack surface keeps growing faster than patch cycles.

3 min read
© 2026 Threat Vectr