The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall SMA1000. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
Tag: CISA Known Exploitable Vulnerabilities Catalog
CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of a vulnerability impacting JFrog Artifactory, tracked as CVE-2026-82329. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)
PaperCut released an Urgent Security Advisory to address two actively exploited vulnerabilities, tracked as CVE-2026-82078 & CVE-2026-81578, impacting all versions of PaperCut NG and PaperCut MF. When chained together, these vulnerabilities can enable pre-authentication remote code execution in the PaperCut Application Server. The flaw originates from a request-confusion/authorization gap. The vendor has mentioned in their … Continue reading “PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)”
CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of Zimbra vulnerability, tracked as CVE-2026-73570. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 24, 2026. The vulnerability exists in the SNMP monitoring component when SNMP notifications are enabled. Successful exploitation of the vulnerability … Continue reading “CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)”
CISA Warns of Apple macOS Vulnerability Exploited in Attack (CVE-2026-65400)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently acknowledged the active exploitation of the macOS vulnerability. Tracked as CVE-2026-65400, the vulnerability affects macOS Tahoe, macOS Sequoia, and macOS Sonoma. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 21, 2026. Alfredo Pesoli via Bynario Atlas discovered and reported the vulnerability to Apple.
Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)
Cisco released a security advisory to address a high-severity vulnerability tracked as CVE-2026-20349. The vulnerability impacts the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause the affected device … Continue reading “Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)”
CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)
CISA has warned U.S. government agencies about an actively exploited vulnerability impacting Cisco Secure Firewall Management Center. CISA added the CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 1, 2026. Successful exploitation of this vulnerability could allow an attacker to log in to the affected system and access sensitive data as … Continue reading “CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)”
JetBrains TeamCity Remote Code Execution Vulnerability (CVE-2026-63077)
JetBrains released a security advisory addressing a critical severity vulnerability impacting TeamCity On-Premises. Tracked as CVE-2026-63077, successful exploitation of the vulnerability may allow an unauthenticated attacker to bypass authentication checks and execute arbitrary operating system commands. JetBrains mentioned in their advisory that they are not aware of any active exploitation of this vulnerability. CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities … Continue reading “JetBrains TeamCity Remote Code Execution Vulnerability (CVE-2026-63077)”
VMware ESX, vCenter, Workstation, and Fusion Multiple Vulnerabilities
Broadcom has released a security advisory addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. Three of these vulnerabilities, tracked as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, have been given critical severity ratings.
WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)
Threat actors have released public exploit code for the WordPress core remote code execution vulnerabilities, named wp2shell. Tracked as CVE-2026-63030 and CVE-2026-60137, the vulnerabilities can be chained together to achieve pre-authentication remote code execution. Adam Kues of Searchlight Cyber discovered and reported the vulnerability to WordPress. The article mentioned that more than 500 million websites use WordPress, which … Continue reading “WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)”