Skip to main content
← All Articles

Tag

#CISA KEV

107 articles

Advertisement

CRITICAL
Vulnerabilities

CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw

CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.

Runtime Rebel Intel
4 min read · May 27, 2026
CRITICAL
Vulnerabilities

CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day

CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.

Runtime Rebel Intel
4 min read · May 27, 2026
HIGH
Vulnerabilities

Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert

CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.

Runtime Rebel Intel
3 min read · May 26, 2026
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog

CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

Runtime Rebel Intel
3 min read · May 23, 2026
CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation
CRITICAL
Vulnerabilities

CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation

CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV. Learn how to mitigate CVE-2025-34291 and CVE-2023-41179 to prevent active exploitation.

Runtime Rebel Intel
4 min read · May 22, 2026
HIGH
Vulnerabilities

CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited

CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.

Runtime Rebel Intel
3 min read · May 21, 2026

Advertisement

CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation

CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.

Runtime Rebel Intel
4 min read · May 15, 2026
Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit
CRITICAL
Vulnerabilities

Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit

CISA adds CVE-2026-20182 to its KEV catalog after reports of active exploitation against Cisco Catalyst SD-WAN Controllers. Critical patch required.

Runtime Rebel Intel
3 min read · May 15, 2026
CRITICAL
Vulnerabilities

CVE-2026-42208: BerriAI LiteLLM SQLi Exploitation — Patch Now

CISA adds CVE-2026-42208, a critical SQL injection vulnerability in BerriAI LiteLLM, to KEV catalog. Active exploitation confirmed.

Runtime Rebel Intel
4 min read · May 8, 2026
CRITICAL
Vulnerabilities

Ivanti EPMM CVE-2023-35078 Zero-Day: Urgent CISA Patch Directive

CISA orders federal agencies to patch Ivanti EPMM CVE-2023-35078 within four days following active zero-day exploitation against government networks.

Runtime Rebel Intel
3 min read · May 8, 2026
CRITICAL
Vulnerabilities

CVE-2026-6973: Ivanti EPMM Exploited in the Wild — Patch Guidance

CISA adds CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile, to the KEV catalog following active exploitation.

Runtime Rebel Intel
3 min read · May 7, 2026
HIGH
Vulnerabilities

CVE-2024-1086: Copy Fail Linux Privilege Escalation Under Exploitation

CISA adds CVE-2024-1086 (Copy Fail) to its KEV catalog after Microsoft observes exploitation of this Linux Netfilter privilege escalation vulnerability.

Runtime Rebel Intel
3 min read · May 4, 2026
CVE-2026-31431: CISA Warns of Linux Local Privilege Escalation Exploit
HIGH
Vulnerabilities

CVE-2026-31431: CISA Warns of Linux Local Privilege Escalation Exploit

CISA adds CVE-2026-31431 to its KEV catalog following active exploitation of a Linux local privilege escalation flaw. Learn how to mitigate root access risks.

Runtime Rebel Intel
3 min read · May 3, 2026
CRITICAL
Vulnerabilities

CVE-2026-31431: Linux Kernel Resource Transfer Vulnerability Actively Exploited

CISA adds CVE-2026-31431, a Linux Kernel incorrect resource transfer vulnerability, to its KEV catalog due to active exploitation. Prioritize remediation.

Runtime Rebel Intel
4 min read · May 1, 2026
CRITICAL
Vulnerabilities

Windows Kernel LPE CVE-2024-21338: Lazarus Group Exploits Zero-Day

CISA adds CVE-2024-21338 to KEV catalog after Lazarus Group exploited the Windows Kernel vulnerability to deploy rootkits and bypass security controls.

Runtime Rebel Intel
3 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

CVE-2024-1708 & CVE-2026-32202: CISA KEV Update — Patch Now

CISA adds CVE-2024-1708 and CVE-2026-32202 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Vulnerabilities

CISA KEV Update: Samsung, SimpleHelp, and D-Link Flaws Exploited

CISA adds four vulnerabilities to its Known Exploited Vulnerabilities catalog, including Samsung MagicINFO 9 and D-Link DIR-823X flaws. Patching is required.

Runtime Rebel Intel
4 min read · Apr 25, 2026
CISA KEV Catalog Adds Exploited Samsung and SimpleHelp Vulnerabilities
HIGH
Vulnerabilities

CISA KEV Catalog Adds Exploited Samsung and SimpleHelp Vulnerabilities

CISA adds four exploited flaws in SimpleHelp, Samsung MagicINFO 9, and D-Link routers to its KEV catalog, mandating remediation by May 2026.

Runtime Rebel Intel
3 min read · Apr 25, 2026
CRITICAL
Vulnerabilities

CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now

CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
HIGH
Vulnerabilities

CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis

CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.

Runtime Rebel Intel
4 min read · Apr 23, 2026
CRITICAL
Vulnerabilities

CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE

Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.

Runtime Rebel Intel
3 min read · Apr 22, 2026
CRITICAL
Vulnerabilities

CISA KEV Update: Eight New Vulnerabilities in Cisco, TeamCity, and Zimbra

CISA adds eight vulnerabilities to the KEV Catalog, including flaws in Cisco SD-WAN and JetBrains TeamCity, requiring immediate federal agency remediation.

Runtime Rebel Intel
3 min read · Apr 21, 2026
CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild
HIGH
Vulnerabilities

CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild

CISA adds 8 vulnerabilities to its KEV catalog, including PaperCut and Cisco SD-WAN Manager flaws, with federal patching deadlines set for May 2026.

Runtime Rebel Intel
3 min read · Apr 21, 2026
CRITICAL
Vulnerabilities

CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild

CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.

Runtime Rebel Intel
3 min read · Apr 17, 2026