“known exploited vulnerabilities” — 37 distilled results

🏛️ CISA Adds One Known Exploited Vulnerability to Catalog 📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,... https://www. cisa.gov/news-events/alerts/20

🏛️ CISA Adds One Known Exploited Vulnerability to Catalog 📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,... https://www.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

🔹 The Hacker News CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws i

S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

CVE-2026-76461: Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes).

Resource spotlight: BleepingComputer Premier coverage on active ransomware campaigns, malware technical breakdowns, OS patches, and practical cybersecurity fixes. Category: Ransomware / Tech Section:

Resource spotlight: BleepingComputer Premier coverage on active ransomware campaigns, malware technical breakdowns, OS patches, and practical cybersecurity fixes. Category: Ransomware / Tech Section: Cybersecurity, Threat Intelligence & Awareness Link: https://www.

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are st

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are strongly urged to apply security patches immediately to prevent unauthorized access and potential compromise.

CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes).

CISA adds multiple critical vulnerabilities to known exploited catalog

Between September 8 and 11, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added six critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Windows, GitLab, JFrog Artifactory, and N-able N-central that allow remote code execution and privilege escalation. Active exploitation of these vulnerabilities has been documented.

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability These types of vulnerabilities are a freque