Vulnerabilities CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities Leading to code execution, authentication bypass, and privilege escalation, the flaws were added to CISA’s KEV list. Ionut ArghireOctober 21, 2025
Vulnerabilities CISA Confirms Exploitation of Latest Oracle EBS Vulnerability The cybersecurity agency has added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsOctober 21, 2025
Vulnerabilities Organizations Warned of Exploited Adobe AEM Forms Vulnerability A public PoC existed when Adobe patched the Experience Manager Forms (AEM Forms) bug in early August. Ionut ArghireOctober 16, 2025
Vulnerabilities Organizations Warned of Exploited Meteobridge Vulnerability Patched in mid-May, the security defect allows remote unauthenticated attackers to execute arbitrary commands with root privileges. Ionut ArghireOctober 3, 2025
Vulnerabilities Organizations Warned of Exploited Sudo Vulnerability The vulnerability could allow local, low-privileged attackers to execute commands with root privileges, leading to full system compromise. Ionut ArghireSeptember 30, 2025
Vulnerabilities Organizations Warned of Exploited Git Vulnerability CISA urges federal agencies to immediately patch an exploited arbitrary file write vulnerability in Git that leads to remote code execution. Ionut ArghireAugust 26, 2025
Vulnerabilities CISA Warns of Attacks Exploiting N-able Vulnerabilities CISA reported becoming aware of attacks exploiting CVE-2025-8875 and CVE-2025-8876 in N-able N-central on the day they were patched. Eduard KovacsAugust 14, 2025
Vulnerabilities Organizations Warned of Exploited PaperCut Flaw Threat actors are exploiting a two-year-old vulnerability in PaperCut that allows them to execute arbitrary code remotely. Ionut ArghireJuly 29, 2025
Vulnerabilities CISA Warns of SysAid Vulnerability Exploitation CISA has added two recent SysAid vulnerabilities, CVE-2025-2776 and CVE-2025-2775, to its KEV catalog. Eduard KovacsJuly 23, 2025
Vulnerabilities CitrixBleed 2 Flaw Poses Unacceptable Risk: CISA CISA considers the recently disclosed CitrixBleed 2 vulnerability an unacceptable risk and has added it to the KEV catalog. Ionut ArghireJuly 14, 2025
Vulnerabilities CISA Warns of Two Exploited TeleMessage Vulnerabilities CISA says two more vulnerabilities in the messaging application TeleMessage TM SGNL have been exploited in the wild. Ionut ArghireJuly 2, 2025
Vulnerabilities CISA Warns AMI BMC Vulnerability Exploited in the Wild CISA is urging federal agencies to patch a recent AMI BMC vulnerability and a half-a-decade-old bug in FortiOS by July 17. Ionut ArghireJune 26, 2025
Vulnerabilities Linux Security: New Flaws Allow Root Access, CISA Warns of Old Bug Exploitation Qualys has disclosed two Linux vulnerabilities that can be chained for full root access, and CISA added a flaw to its KEV catalog. Eduard KovacsJune 18, 2025
Vulnerabilities Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers CISA warns that a vulnerability impacting multiple discontinued TP-Link router models is exploited in the wild. Ionut ArghireJune 17, 2025
Incident Response Vulnerabilities in CISA KEV Are Not Equally Critical: Report New report says organizations should always consider environmental context when assessing the impact of vulnerabilities in CISA KEV catalog. Ionut ArghireMay 28, 2025
Artificial Intelligence Critical Vulnerability in AI Builder Langflow Under Attack CISA warns organizations that threat actors are exploiting a critical-severity vulnerability in low-code AI builder Langflow. Ionut ArghireMay 6, 2025
Vulnerabilities PoC Published for Exploited SonicWall Vulnerabilities PoC code targeting two exploited SonicWall flaws was published just CISA added them to the KEV catalog. Ionut ArghireMay 5, 2025
Vulnerabilities CISA Warns of Exploited Broadcom, Commvault Vulnerabilities CISA urges immediate patching for recently disclosed Broadcom, Commvault, and Qualitia vulnerabilities exploited in the wild. Ionut ArghireApril 29, 2025
Vulnerabilities CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days CISA has added fresh CentreStack and Windows CLFS vulnerabilities to the Known Exploited Vulnerabilities catalog. Ionut ArghireApril 9, 2025
Vulnerabilities CISA Warns of Exploited Nakivo Vulnerability CISA has added an absolute path traversal bug in Nakivo Backup and Replication to its Known Exploited Vulnerabilities list. Ionut ArghireMarch 20, 2025