Advertisement
CVE-2025-66376: ZCS Cross-Site Scripting Actively Exploited
CISA adds CVE-2025-66376, a Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting vulnerability, to its KEV Catalog due to active exploitation. Immediate
CVE-2024-4510: Zimbra Collaboration Suite XSS Exploitation Guide
CISA adds CVE-2024-4510 to the KEV catalog following active exploitation of a Zimbra Collaboration Suite XSS vulnerability. Patch ZCS version 9.0.0 today.
CVE-2024-50498: Wing FTP Server Exploited in RCE Chains — Patch Now
CISA adds CVE-2024-50498 to its KEV catalog after reports of active exploitation. Learn how to secure Wing FTP Server versions prior to 7.5.0 from RCE chains.
Ivanti EPM CVE-2024-29824 Exploited: Technical Analysis and Patching
CISA warns of active exploitation of CVE-2024-29824 in Ivanti Endpoint Manager. Secure your Core server with our technical analysis and mitigation guide.
CVE-2024-29847: Ivanti EPM RCE Under Active Exploitation - Patch Now
CISA warns of active exploitation of a critical Ivanti EPM vulnerability (CVE-2024-29847). Learn how to mitigate this unauthenticated RCE threat immediately.

CISA Flags SolarWinds, Ivanti, and Workspace One Flaws in KEV Update
CISA adds vulnerabilities in SolarWinds, Ivanti, and Omnissa Workspace One UEM to its Known Exploited Vulnerabilities catalog following active exploitation.
CVE-2026-1603: CISA Warns of Active Ivanti and SolarWinds Exploitation
CISA adds CVE-2026-1603, CVE-2025-26399, and CVE-2021-22054 to the KEV catalog, requiring immediate remediation for Ivanti, SolarWinds, and Omnissa systems.
CVE-2023-20887: VMware Aria Operations for Networks RCE Exploit Guide
CISA adds CVE-2023-20887 to its KEV catalog. Learn how to detect and patch this critical RCE flaw in VMware Aria Operations for Networks.
CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog
CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.

CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.
CISA Adds Roundcube Webmail Vulnerabilities to KEV Catalog
CISA adds CVE-2025-49113 and CVE-2025-68461 to its Known Exploited Vulnerabilities catalog, signaling active exploitation of Roundcube Webmail systems.
CISA Catalogs Critical Roundcube Deserialization Vulnerability Under Active Exploitation
CISA has added CVE-2025-49113 to the Known Exploited Vulnerabilities catalog, addressing a critical RCE flaw in Roundcube webmail software resulting from untrusted data deserialization.