Tag

#known exploited vulnerabilities

7 stories taggedknown exploited vulnerabilities.

Illustration: an empty government briefing room at dusk
Policy & Regulation

CISA Is Scrapping Its Weekly Vulnerability Bulletin

The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

3 min read
A close-up of a developer's desk with multiple monitors displaying code and warning alerts, with a red notification banner visible on the central screen, urgent
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity

A software tool used by thousands of development teams has a severe security hole that attackers are already using. The US government is giving federal agencies three days to fix it.

3 min read
A federal government IT operations center with multiple screens displaying three different vulnerability alerts simultaneously—Langflow, N-central, and Tomcat p
Vulnerabilities

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack

Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

4 min read
A government IT department frantically updating systems at night, multiple technicians at workstations with security patches being deployed across networks, urg
Vulnerabilities

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago

CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

3 min read
Illustration: a dark server rack in a data centre with a single amber warning light glowing on one rack unit
Vulnerabilities

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack

Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

3 min read
Illustration: a server room corridor
Vulnerabilities

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws

Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

3 min read
Illustration for the story: CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
Vulnerabilities

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint

A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

3 min read
© 2026 Threat Vectr