Advertisement
CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw
CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.
CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day
CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation
CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV. Learn how to mitigate CVE-2025-34291 and CVE-2023-41179 to prevent active exploitation.
CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation
CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.
CVE-2026-42208: BerriAI LiteLLM SQLi Exploitation — Patch Now
CISA adds CVE-2026-42208, a critical SQL injection vulnerability in BerriAI LiteLLM, to KEV catalog. Active exploitation confirmed. Timely patching is essential for all

CVE-2026-31431: CISA Warns of Linux Local Privilege Escalation Exploit
CISA adds CVE-2026-31431 to its KEV catalog following active exploitation of a Linux local privilege escalation flaw. Learn how to mitigate root access risks.
CVE-2026-31431: Linux Kernel Resource Transfer Vulnerability Actively Exploited
CISA adds CVE-2026-31431, a Linux Kernel incorrect resource transfer vulnerability, to its KEV catalog due to active exploitation. Prioritize remediation.

CISA KEV Catalog Adds Exploited Samsung and SimpleHelp Vulnerabilities
CISA adds four exploited flaws in SimpleHelp, Samsung MagicINFO 9, and D-Link routers to its KEV catalog, mandating remediation by May 2026.
CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis
CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.
CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE
Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.
CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild
CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.