Tag

#KEV catalog

8 stories taggedKEV catalog.

Illustration: a dimly lit server room aisle with rows of rack-mounted Linux servers
Policy & Regulation

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws

The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

4 min read
Multiple server racks in a secure data center with urgent patch deployment notices displayed across monitoring dashboards, showing critical vulnerability indica
Vulnerabilities

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw

The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

3 min read
A corporate IT storage room filled with servers and networking equipment, many with outdated stickers and faded labels, showing years of accumulated patches and
Vulnerabilities

CISA: Most Breaches Still Start With Old, Unpatched Bugs

A new review from the US cyber agency finds attackers rarely need clever tricks. They scan for known, exposed flaws that companies never got around to fixing.

3 min read
A code repository interface showing file directories and command execution logs, with a highlighted patch notice dated late July and a federal agency seal in th
Vulnerabilities

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands

A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

3 min read
Multiple windows showing security patch notifications and system update dialogs stacked across a desktop environment, with warning badges highlighted in red and
Vulnerabilities

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

4 min read
Illustration: a dimly lit server room with rack-mounted network security appliances, blinking amber status lights
Vulnerabilities

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint

Two Fortinet FortiSandbox command-injection flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

3 min read
Illustration: A row of black server rack units with blinking amber and red indicator lights in a dimly lit data centre
Vulnerabilities

CISA Orders Federal Agencies to Patch Palo Alto Firewall Flaw Being Exploited Now

A misconfigured URL filtering setting in Palo Alto Networks firewall software is letting attackers weaponise the firewalls themselves, turning them into unwitting cannons pointed at other targets.

3 min read
Illustration: a dimly lit government server room, rows of racks with faint blue and amber status LEDs
Policy & Regulation

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin

A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

3 min read
© 2026 Threat Vectr