Skip to main content

Tag: known exploited vulnerabilities

38 articles

Empty computer workstation on a neutral-colored desk in a generic office setting with a laptop and peripherals.

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products

The US Cybersecurity and Infrastructure Security Agency (CISA) has just sounded the alarm, adding six new vulnerabilities to its Known Exploited Vulnerabilities catalog in a single day - a stark reminder that threat actors are relentlessly targeting both old and newly discovered software weaknesses. This urgent move underscores the need for immediate action to patch these flaws and prevent exploitation.

Analyst 207
Security operations center with large screen displaying system monitoring dashboard.

CISA Catalog Adds Six Exploited Flaws

Active exploitation is underway for six newly cataloged vulnerabilities, including a high-severity Citrix NetScaler flaw that's seen 36 exploitation attempts in just 12 days. The US Cybersecurity and Infrastructure Security Agency has added these flaws to its Known Exploited Vulnerabilities catalog, signaling urgent attention is needed.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room, with one server slightly ajar, suggesting…

Gitea Flaw Exploited to Deploy Miner-Like Payload

Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Analyst 207
Rows of rack-mounted servers and IT equipment in a brightly-lit, empty data center interior.

CISA Mandates Patching of Exploited TrueConf Server Flaws

Don't wait until it's too late: CISA has issued a two-week deadline for U.S. federal agencies to patch two critical TrueConf Server vulnerabilities that hackers are actively exploiting to execute malicious scripts remotely. With a September 3 remediation deadline looming, prioritize patching now to safeguard your systems.

Analyst 207
Empty server room with rows of equipment racks and computer servers under fluorescent lighting.

CISA Warns of Active Exploitation of Critical Flaws in macOS, SharePoint, vCenter, and Microsoft IKE

Critical flaws in macOS, SharePoint, vCenter, and Microsoft IKE are under active attack, with 361 victim IP addresses across 47 countries already compromised. CISA has sounded the alarm, adding these vulnerabilities to its Known Exploited Vulnerabilities catalog.

Analyst 207
Laptop screen shows blurred web browser with network router in background.

CISA Warns of Actively Exploited Ray Flaw Enabling Browser-Based RCE

A critical vulnerability, CVE-2025-62593, is under active exploitation, allowing hackers to execute remote code through web browsers like Firefox and Safari by using a clever DNS rebinding attack. This high-severity flaw, with a CVSS score of 9.4, stems from a weakness in the Ray project's defenses against browser-based attacks.

Analyst 207
Network operations center equipment rack with loadmaster device and cabling.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

Analyst 207
Blurred industrial control system in foreground, with brightly-lit equipment rows in the background.

IBM Langflow AI Platform Under Active Exploitation

A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

Analyst 207
Rack of computer equipment with monitors in a neutral industrial setting.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws

Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

Analyst 207
Brightly-lit industrial control system terminal on a factory floor.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

Analyst 207
Research and development area with a workstation and laptop in the foreground and blurred AI equipment in the background.

CISA Targets Langflow Flaw in Urgent Patch Directive

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent patch directive for a vulnerability in the Langflow visual framework, used to build AI agents, after recording over 220 exploitation attempts in just one day. This critical flaw, tracked as CVE-2026-0770, has already been exploited by multiple attackers, prompting immediate action.

Analyst 207
Cluttered tech lab with AI equipment, laptop screen shows AI model file access.

ENCFORGE Ransomware Targets AI Model Files in Langflow Attack

A new ransomware called ENCFORGE is targeting AI model files, exploiting a high-severity flaw in Langflow to deploy a custom-built payload that threatens machine learning systems. This highly specialized attack focuses on encrypting critical AI data, including PyTorch, TensorFlow, and Hugging Face files.

Analyst 207
Network device on a rack in a brightly-lit data center environment.

CISA Warns of Active Exploits Targeting FortiSandbox Flaws

Critical FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, are under active attack by hackers, allowing them to execute malicious commands without needing login credentials. These severe vulnerabilities, scoring 9.1, require immediate attention to prevent devastating remote code execution attacks.

Analyst 207
Technician applies security patch to computer system, symbolizing vulnerability fix.

CISA Orders Emergency Patch for Exploited Fortinet Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring federal agencies to patch or mitigate two critical Fortinet vulnerabilities within a tight three-day window, underscoring the severity of these flaws. This urgent action follows the discovery of a critical OS command injection vulnerability in FortiSandbox, allowing attackers to execute unauthorized code or commands.

Analyst 207
Attackers Exploit Joomla Extension Bugs with Perfect 10 Scores

Attackers Exploit Joomla Extension Bugs with Perfect 10 Scores

Critical vulnerabilities in two popular Joomla extensions have been exploited in the wild, allowing attackers to gain remote control of affected sites by uploading malicious files. The Cybersecurity and Infrastructure Security Agency has sounded the alarm, adding the flaws to its Known Exploited Vulnerabilities catalog.

Analyst 207
Web server setup under attack in a bright office environment.

CISA Warns of Exploited Flaws in Joomla Extensions

Stay safe online: a critical vulnerability in the iCagenda extension for Joomla can allow attackers to upload malicious files and take control of your website, leading to data theft and total site compromise. CISA warns that this flaw, tracked as CVE-2026-48939, is being actively exploited, so take action now to protect your site.

Analyst 207
Officials gather around a podium and large screen displaying a blurred SharePoint interface.

CISA Flags SharePoint Flaw as Exploitable

Microsoft initially downplayed the risk of a SharePoint vulnerability, saying exploitation was less likely, but the Cybersecurity and Infrastructure Security Agency has since escalated the flaw to its list of known exploited vulnerabilities. This move signals a heightened sense of urgency for organizations to address the potentially critical issue.

Analyst 207
A lone computer workstation sits in a vast, empty IT room with rows of server racks in the background.

CISA Warns of Active SharePoint RCE Exploitation

CISA warns that a high-severity vulnerability in Microsoft SharePoint Server, known as CVE-2026-45659, is being actively exploited, allowing authorized attackers to execute code remotely. This critical flaw, patched by Microsoft in May, requires immediate attention to prevent network breaches.

Analyst 207
Windows computer setup on office desk with laptop and keyboard in focus, near a whiteboard with network diagram.

Ransomware gangs exploit Windows BlueHammer flaw

Ransomware gangs are actively exploiting a critical Microsoft Defender flaw, nicknamed BlueHammer, which has been added to CISA's list of Known Exploited Vulnerabilities. This vulnerability is a prime target for malicious cyber actors, posing a significant risk to those who haven't yet applied the necessary patches.

Analyst 207
Ubiquiti UniFi OS device in a small business office setting with ambient daylight.

CISA Warns of Actively Exploited Ubiquiti Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are actively exploiting security flaws in Ubiquiti UniFi OS devices, posing a significant threat to system security. Federal agencies have just three days to apply crucial updates or recommended fixes to avoid potential breaches.

Analyst 207
Dimly lit server room with outdated equipment and exposed cables.

Legacy Infrastructure Exposes AI Agents to Hijacking Risks

Legacy infrastructure can put your AI agents at risk of hijacking, as seen with CVE-2025-24813, a remote code execution flaw that lets attackers turn a routine server compromise into a full takeover. An unpatched Internet-facing Apache Tomcat server is all it takes to expose your enterprise to this threat.

Analyst 207
Technician in a network operations room checking equipment surrounding a central router.

Cisco Disrupts Active Exploitation of SD-WAN Manager Flaw

Cisco is taking swift action to combat the active exploitation of a medium-severity flaw in its SD-WAN Manager, known as CVE-2026-20262, which could let hackers create or overwrite files on affected systems. Federal agencies have until June 29, 2026 to remediate the vulnerability.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room with a highlighted server in the foreground.

LiteLLM Flaw Exploited in Wild, Enables Unauthenticated RCE

A high-severity flaw in BerriAI's LiteLLM, known as CVE-2026-42271, has been actively exploited, allowing unauthenticated users to execute commands remotely. This critical vulnerability affects LiteLLM versions 1.74.2 to 1.83.7 and has been deemed a major security risk.

Analyst 207
Server racks and computer hardware in a dimly lit e-commerce IT area.

CISA Warns of Exploited Magento Extension Flaw

A critical flaw in the Mirasvit Full Page Cache Warmer Magento extension, tracked as CVE-2026-45247, has been exploited by hackers, allowing them to execute remote code without authentication. This vulnerability, rated 9.8 on the CVSS scale, enables attackers to wreak havoc by supplying a malicious PHP object in the CacheWarmer cookie.

Analyst 207