
CISA orders feds to patch actively exploited Zyxel flaw by Thursday
CISA has ordered U.S. federal agencies to patch a critical Zyxel GS1900 series switch vulnerability by Thursday. The flaw is being actively exploited by attackers for data theft.
Stories tagged “Cisa.”
30 stories

CISA has ordered U.S. federal agencies to patch a critical Zyxel GS1900 series switch vulnerability by Thursday. The flaw is being actively exploited by attackers for data theft.

CISA warns of hackers exploiting a critical ScreenConnect vulnerability, affecting over 1,000 unpatched instances globally.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.

Microsoft addressed a record 974 vulnerabilities across its software portfolio, including two actively exploited Windows zero-day flaws, in its latest Patch Tuesday update.

CISA has added a maximum-severity pre-authentication remote code execution (RCE) flaw in N-able N-central (CVE-2026-86218) to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it by September 11, 2026, due to active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.

CISA has added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in Citrix NetScaler, Linux Kernel, and Microsoft SQL Server, urging federal agencies to patch them immediately.

Hackers exploit two Microsoft SharePoint vulnerabilities to execute code, using proof-of-concept exploits.

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The Zimbra security team patched the security flaw (tracked as CVE-2026-735…
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA updates its catalog with two new vulnerabilities identified as active threats.

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability. This vulnerability can be used by attackers without privileges to remotely access internal services or cloud metadata…
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability is a Server-Side Request Forgery (SSRF) vulnerability in MLflow.

CISA, HHS, and FBI reported that the Medusa ransomware gang has breached over 500 critical infrastructure organizations in the United States since June 2021, an increase from a previous report.
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterpr…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are exploiting a high-severity Windows Task Host vulnerability. The vulnerability, tracked as CVE-2025-60710, allows local attackers with basic user permissions to gain SY…
The Trump administration's cuts to the Cybersecurity and Infrastructure Security Agency (CISA) have left the US vulnerable to cyberattacks, particularly from Iran, which has been targeting US water and wastewater systems. CISA's budget was reduced and its staff cut by one…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a popular Application Delivery Controller (ADC) and server load balancer us…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of hackers exploiting vulnerabilities in IBM Langflow, N-central, and Apache Tomcat. The agency has given federal agencies three days to mitigate the vulnerabilities.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability is CVE-2026-63077, a JetBrains TeamCity Deserialization of Untrusted Data Vulnerability.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. These vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2026-18577, is an authentication bypass using an alternate path or channel in N-able N-central.

Cyberattacks have hit water facilities in seven states across the US, causing flooding and loss of water pressure. The FBI and EPA warn that hackers are targeting critical infrastructure, specifically Programmable Logic Controllers (PLCs).

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. The agency's urgent alert comes after hackers disr…
2026 Minimum Elements for a Software Bill of Materials (SBOM)
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance on the 2026 Minimum Elements for a Software Bill of Materials (SBOM). This updates and replaces the minimum elements for an SBOM published by the Na…
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability is a use of hard-coded password in Cisco Secure Firewall Management Center.
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
CISA has issued an advisory for multiple vulnerabilities found in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP firmware version V3.1.6. Siemens is preparing fixes and recommends countermeasures for affected products.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerabilities are CVE-2025-68686 and CVE-2026-16812.
Weintek cMT3092X | CISA
CISA has identified vulnerabilities in Weintek cMT3092X that could allow a non-privileged user to escalate privileges or view the credentials of other users. The affected versions are cMT3092X firmware <20210218 and Weintek EasyWeb <v2.1.20. Weintek recommends users apply…
Panduit IntraVUE Vulnerabilities Exposed: Multiple Flaws in Industrial Control System
CISA has identified multiple vulnerabilities in Panduit IntraVUE, a industrial control system. The vulnerabilities, including plaintext storage of a password, unintended proxy or intermediary, exposure of sensitive system information, and inadequate encryption strength, c…
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. These vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.