<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #CISA KEV</title><description>Cybersecurity articles tagged #CISA KEV on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</guid><description>A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.</description><pubDate>Wed, 02 Sep 2026 19:13:21 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>SSRF</category><category>Vulnerability</category><category>CISA KEV</category></item><item><title>CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection</title><link>https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</guid><description>Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.</description><pubDate>Wed, 02 Sep 2026 19:12:29 GMT</pubDate><category>CVE-2026-9586</category><category>Sangoma Switchvox</category><category>SQL Injection</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-49869: Kestra OSS OS Command Injection Exploited</title><link>https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</guid><description>CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.</description><pubDate>Wed, 02 Sep 2026 19:11:22 GMT</pubDate><category>CVE-2026-49869</category><category>Kestra OSS</category><category>OS Command Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2026-59822: BerriAI LiteLLM Authentication Bypass</title><link>https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</guid><description>BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.</description><pubDate>Wed, 02 Sep 2026 19:09:55 GMT</pubDate><category>CVE-2026-59822</category><category>BerriAI LiteLLM</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Improper Authentication</category></item><item><title>CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data</title><link>https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</guid><description>CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.</description><pubDate>Tue, 01 Sep 2026 02:58:41 GMT</pubDate><category>CVE-2021-23758</category><category>Ajax NET Professional</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-66384: JFrog Artifactory Path Traversal Exploit</title><link>https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</guid><description>CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 02:58:16 GMT</pubDate><category>CVE-2026-66384</category><category>JFrog Artifactory</category><category>Path Traversal</category><category>CISA KEV</category><category>Supply Chain Attack</category></item><item><title>CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</guid><description>CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.</description><pubDate>Tue, 01 Sep 2026 02:57:10 GMT</pubDate><category>CVE-2026-53362</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>IPv6</category><category>CISA KEV</category></item><item><title>CVE-2026-60004: Gitea Code Injection Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</guid><description>CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.</description><pubDate>Wed, 26 Aug 2026 00:45:21 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-60004</category><category>Gitea</category><category>Code Injection</category></item><item><title>CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth</title><link>https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</guid><description>CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.</description><pubDate>Fri, 21 Aug 2026 00:48:00 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-72529</category><category>TrueConf Server</category><category>Missing Authentication</category></item><item><title>CVE-2026-72530: TrueConf Server Remote Code Execution</title><link>https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</guid><description>CISA confirms active exploitation of CVE-2026-72530, a TrueConf Server code injection flaw leading to remote code execution. Immediate patching is critical.</description><pubDate>Fri, 21 Aug 2026 00:47:12 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>Vulnerability Management</category><category>CVE-2026-72530</category><category>TrueConf Server</category></item><item><title>CVE-2026-33824: Microsoft IKE Double Free RCE Exploit</title><link>https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</guid><description>CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.</description><pubDate>Wed, 19 Aug 2026 00:43:34 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-33824</category><category>Microsoft IKE</category><category>Double Free</category></item><item><title>CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild</title><link>https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</guid><description>CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.</description><pubDate>Mon, 17 Aug 2026 16:20:50 GMT</pubDate><category>Remote Code Execution</category><category>RCE</category><category>CISA KEV</category><category>CVE-2025-62593</category><category>Ray Project</category></item><item><title>CVE-2026-72898: Metabase SQL Injection Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</guid><description>CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.</description><pubDate>Wed, 12 Aug 2026 01:08:08 GMT</pubDate><category>CVE-2026-72898</category><category>Metabase</category><category>SQL Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit</title><link>https://runtimerebel.com/blog/cve-2026-20349-cisco-asa-ftd-dos-vulnerability-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20349-cisco-asa-ftd-dos-vulnerability-under-active-exploit</guid><description>CISA warns of active exploitation of CVE-2026-20349, a heap inspection vulnerability causing DoS in Cisco ASA and FTD devices.</description><pubDate>Wed, 12 Aug 2026 01:07:05 GMT</pubDate><category>Cisco ASA</category><category>Denial of Service</category><category>CISA KEV</category><category>CVE-2026-20349</category><category>Cisco FTD</category></item><item><title>CVE-2026-63077: JetBrains TeamCity RCE via Deserialization</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</guid><description>CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.</description><pubDate>Tue, 11 Aug 2026 16:54:33 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains TeamCity</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-8037: Progress LoadMaster Command Injection RCE</title><link>https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</guid><description>Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.</description><pubDate>Sat, 08 Aug 2026 01:04:01 GMT</pubDate><category>Command Injection</category><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-8037</category><category>Progress LoadMaster</category></item><item><title>CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities</title><link>https://runtimerebel.com/blog/cisa-warns-actively-exploited-langflow-n-central-and-tomcat-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-actively-exploited-langflow-n-central-and-tomcat-vulnerabilities</guid><description>CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.</description><pubDate>Wed, 05 Aug 2026 10:27:25 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-9198</category><category>CVE-2026-18556</category><category>CVE-2026-18577</category><category>CVE-2026-34486</category></item><item><title>CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</guid><description>CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.</description><pubDate>Tue, 04 Aug 2026 17:33:39 GMT</pubDate><category>Authentication Bypass</category><category>CISA KEV</category><category>Exploitation</category><category>CVE-2026-18556</category><category>N Able N Central</category></item><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</guid><description>CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…</description><pubDate>Sun, 02 Aug 2026 02:54:04 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-16232</category><category>Check Point SmartConsole</category><category>Improper Authentication</category><category>Admin Bypass</category></item><item><title>CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence</title><link>https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</guid><description>CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.</description><pubDate>Fri, 31 Jul 2026 10:43:21 GMT</pubDate><category>CVE-2025-68686</category><category>Fortinet</category><category>Fortios</category><category>Information Exposure</category><category>Patch Bypass</category><category>Post Exploitation</category><category>CISA KEV</category><category>CWE-200</category></item><item><title>CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</guid><description>CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.</description><pubDate>Fri, 31 Jul 2026 10:42:09 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco Secure Firewall Management Center</category><category>Hard Coded Password</category><category>Authentication Bypass</category><category>CISA KEV</category></item><item><title>Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited</title><link>https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</guid><description>CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.</description><pubDate>Thu, 30 Jul 2026 06:29:42 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco</category><category>Firewall Management Center</category><category>CISA KEV</category><category>Static Credentials</category></item><item><title>CVE-2026-58644: SharePoint RCE Zero-Day Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</guid><description>CISA adds CVE-2026-58644, a critical Microsoft SharePoint Server deserialization RCE vulnerability with a CVSS 9.8, to its Known Exploited Vulnerabilities catalog.</description><pubDate>Fri, 17 Jul 2026 09:58:24 GMT</pubDate><category>CVE-2026-58644</category><category>SharePoint</category><category>Microsoft</category><category>CISA KEV</category><category>RCE</category></item><item><title>Microsoft SharePoint RCE via CVE-2024-38094: Mitigation Guide</title><link>https://runtimerebel.com/blog/microsoft-sharepoint-rce-via-cve-2024-38094-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-sharepoint-rce-via-cve-2024-38094-mitigation-guide</guid><description>CISA adds three exploited SharePoint vulnerabilities to the KEV catalog, including CVE-2024-38094. Learn how to detect and mitigate these critical RCE flaws.</description><pubDate>Wed, 15 Jul 2026 17:22:02 GMT</pubDate><category>CVE-2024-38094</category><category>CVE-2024-43461</category><category>CVE-2023-24955</category><category>SharePoint</category><category>CISA KEV</category></item><item><title>CVE-2023-29357: CISA Warns of Active SharePoint Exploit Chain</title><link>https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</guid><description>CISA urges immediate patching of CVE-2023-29357 and CVE-2023-24955 in SharePoint Server due to active exploitation for remote code execution.</description><pubDate>Wed, 15 Jul 2026 10:05:47 GMT</pubDate><category>CVE-2023-29357</category><category>CVE-2023-24955</category><category>Microsoft SharePoint</category><category>CISA KEV</category></item><item><title>Joomla RCE via CVE-2026-48939 and CVE-2026-38294 — Mitigation Guide</title><link>https://runtimerebel.com/blog/joomla-rce-via-cve-2026-48939-and-cve-2026-38294-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/joomla-rce-via-cve-2026-48939-and-cve-2026-38294-mitigation-guide</guid><description>CISA adds CVE-2026-48939 and CVE-2026-38294 to KEV after zero-day exploitation of Joomla iCagenda and Balbooa Forms extensions. Patch immediately.</description><pubDate>Mon, 13 Jul 2026 11:18:48 GMT</pubDate><category>CVE-2026-48939</category><category>CVE-2026-38294</category><category>Joomla</category><category>iCagenda</category><category>Balbooa Forms</category><category>CISA KEV</category></item><item><title>CVE-2024-37014: CISA Orders Federal Agencies to Patch Langflow</title><link>https://runtimerebel.com/blog/cve-2024-37014-cisa-orders-federal-agencies-to-patch-langflow</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-37014-cisa-orders-federal-agencies-to-patch-langflow</guid><description>CISA added CVE-2024-37014, a critical authentication bypass in the Langflow AI framework, to its KEV catalog following reports of active exploitation.</description><pubDate>Wed, 08 Jul 2026 10:23:08 GMT</pubDate><category>CVE-2024-37014</category><category>Langflow</category><category>CISA KEV</category><category>AI Security</category></item><item><title>CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</guid><description>CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.</description><pubDate>Wed, 08 Jul 2026 06:30:23 GMT</pubDate><category>CVE-2026-48282</category><category>Adobe ColdFusion</category><category>Path Traversal</category><category>RCE</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</guid><description>CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.</description><pubDate>Thu, 02 Jul 2026 07:34:50 GMT</pubDate><category>CVE-2026-45659</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now</title><link>https://runtimerebel.com/blog/windows-bluehammer-flaw-exploited-by-ransomware-gangs-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-bluehammer-flaw-exploited-by-ransomware-gangs-patch-now</guid><description>CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.</description><pubDate>Tue, 30 Jun 2026 09:16:59 GMT</pubDate><category>Microsoft Defender</category><category>BlueHammer</category><category>CISA KEV</category><category>Ransomware</category><category>Privilege Escalation</category></item><item><title>CVE-2022-25247: PTC Windchill RCE Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2022-25247-ptc-windchill-rce-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2022-25247-ptc-windchill-rce-exploited-in-the-wild</guid><description>CISA warns of active exploitation of CVE-2022-25247, an RCE flaw in PTC Windchill PLM software. Learn how to detect and mitigate this critical threat.</description><pubDate>Fri, 26 Jun 2026 09:18:55 GMT</pubDate><category>CVE-2022-25247</category><category>PTC Windchill</category><category>RCE</category><category>CISA KEV</category><category>Manufacturing Security</category></item><item><title>Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide</title><link>https://runtimerebel.com/blog/oracle-peoplesoft-cve-2026-35273-exploit-cisa-kev-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-peoplesoft-cve-2026-35273-exploit-cisa-kev-mitigation-guide</guid><description>CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.</description><pubDate>Sat, 13 Jun 2026 09:15:30 GMT</pubDate><category>CVE-2026-35273</category><category>Oracle PeopleSoft</category><category>CISA KEV</category><category>Vulnerability Management</category><category>PeopleTools</category></item><item><title>Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate</title><link>https://runtimerebel.com/blog/ivanti-sentry-cve-2023-35081-cisa-issues-urgent-3-day-patch-mandate</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-sentry-cve-2023-35081-cisa-issues-urgent-3-day-patch-mandate</guid><description>CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.</description><pubDate>Fri, 12 Jun 2026 09:33:30 GMT</pubDate><category>Ivanti Sentry</category><category>CVE-2023-35081</category><category>CISA KEV</category><category>Path Traversal</category><category>Rce Chain</category></item><item><title>CISA Adds CVE-2026-42271 and CVE-2026-50751 to KEV Catalog</title><link>https://runtimerebel.com/blog/cisa-adds-cve-2026-42271-and-cve-2026-50751-to-kev-catalog</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-adds-cve-2026-42271-and-cve-2026-50751-to-kev-catalog</guid><description>CISA warns of active exploitation involving BerriAI LiteLLM and Check Point Security Gateways. Learn how to mitigate these critical security flaws.</description><pubDate>Tue, 09 Jun 2026 09:18:40 GMT</pubDate><category>CVE-2026-42271</category><category>CVE-2026-50751</category><category>CISA KEV</category><category>BerriAI</category><category>Check Point</category><category>Command Injection</category></item><item><title>CVE-2026-42271: BerriAI LiteLLM RCE Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-42271-berriai-litellm-rce-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42271-berriai-litellm-rce-exploited-in-the-wild</guid><description>CISA warns of active exploitation of CVE-2026-42271 in BerriAI LiteLLM. This command injection flaw allows attackers to achieve RCE and compromise AI proxies.</description><pubDate>Tue, 09 Jun 2026 09:15:35 GMT</pubDate><category>CVE-2026-42271</category><category>LiteLLM</category><category>BerriAI</category><category>CISA KEV</category><category>RCE</category><category>Command Injection</category></item><item><title>SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV</title><link>https://runtimerebel.com/blog/solarwinds-serv-u-dos-vulnerability-cve-2026-28318-added-to-cisa-kev</link><guid isPermaLink="true">https://runtimerebel.com/blog/solarwinds-serv-u-dos-vulnerability-cve-2026-28318-added-to-cisa-kev</guid><description>CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.</description><pubDate>Sat, 06 Jun 2026 08:59:14 GMT</pubDate><category>SolarWinds</category><category>Serv U</category><category>CVE-2026-28318</category><category>CISA KEV</category><category>DoS</category></item><item><title>CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit</title><link>https://runtimerebel.com/blog/cve-2026-28318-solarwinds-serv-u-uncontrolled-resource-consumption-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-28318-solarwinds-serv-u-uncontrolled-resource-consumption-exploit</guid><description>CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.</description><pubDate>Fri, 05 Jun 2026 20:42:27 GMT</pubDate><category>CVE-2026-28318</category><category>SolarWinds Serv U</category><category>Uncontrolled Resource Consumption</category><category>CISA KEV</category></item><item><title>CVE-2024-28995: SolarWinds Serv-U Exploit Leads to Server Crashes</title><link>https://runtimerebel.com/blog/cve-2024-28995-solarwinds-serv-u-exploit-leads-to-server-crashes</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-28995-solarwinds-serv-u-exploit-leads-to-server-crashes</guid><description>CISA warns of active exploitation of SolarWinds Serv-U CVE-2024-28995. Attackers are leveraging this directory traversal flaw to crash vulnerable servers.</description><pubDate>Fri, 05 Jun 2026 20:41:11 GMT</pubDate><category>CVE-2024-28995</category><category>SolarWinds</category><category>Serv U</category><category>CISA KEV</category><category>Directory Traversal</category></item><item><title>CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis</title><link>https://runtimerebel.com/blog/cve-2026-45247-magento-mirasvit-cache-warmer-rce-exploit-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45247-magento-mirasvit-cache-warmer-rce-exploit-analysis</guid><description>CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.</description><pubDate>Thu, 04 Jun 2026 09:25:50 GMT</pubDate><category>CVE-2026-45247</category><category>Magento</category><category>Mirasvit</category><category>RCE</category><category>CISA KEV</category><category>Deserialization</category></item><item><title>CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-45247-mirasvit-full-page-cache-warmer-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45247-mirasvit-full-page-cache-warmer-exploited-patch-now</guid><description>CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.</description><pubDate>Wed, 03 Jun 2026 17:47:53 GMT</pubDate><category>CVE-2026-45247</category><category>Mirasvit</category><category>Magento</category><category>CISA KEV</category><category>RCE</category><category>Deserialization</category></item><item><title>Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626</title><link>https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</guid><description>CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.</description><pubDate>Wed, 03 Jun 2026 17:46:16 GMT</pubDate><category>CVE-2024-36971</category><category>CVE-2024-21626</category><category>CISA KEV</category><category>Android Security</category><category>Linux Kernel</category><category>Container Breakout</category></item><item><title>CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595</title><link>https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</guid><description>CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.</description><pubDate>Tue, 02 Jun 2026 21:13:18 GMT</pubDate><category>CVE-2022-0492</category><category>CVE-2025-48595</category><category>CISA KEV</category><category>Linux Kernel</category><category>Android Security</category></item><item><title>CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation</title><link>https://runtimerebel.com/blog/cve-2022-21371-cisa-warns-of-oracle-weblogic-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2022-21371-cisa-warns-of-oracle-weblogic-exploitation</guid><description>CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.</description><pubDate>Tue, 02 Jun 2026 13:27:03 GMT</pubDate><category>CVE-2022-21371</category><category>Oracle WebLogic</category><category>CISA KEV</category><category>Information Disclosure</category></item><item><title>CVE-2024-21182: Oracle WebLogic Server Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2024-21182-oracle-weblogic-server-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21182-oracle-weblogic-server-under-active-exploitation</guid><description>CISA added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its KEV Catalog due to active exploitation. Immediate patching required.</description><pubDate>Mon, 01 Jun 2026 18:11:46 GMT</pubDate><category>CVE-2024-21182</category><category>Oracle WebLogic Server</category><category>CISA KEV</category><category>Active Exploitation</category><category>Unspecified Vulnerability</category></item><item><title>CVE-2026-0257: Palo Alto PAN-OS Auth Bypass Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</guid><description>CISA adds CVE-2026-0257, an actively exploited authentication bypass in Palo Alto Networks PAN-OS, to its KEV catalog.</description><pubDate>Fri, 29 May 2026 20:55:29 GMT</pubDate><category>CVE-2026-0257</category><category>Palo Alto Networks</category><category>PAN OS</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>Actively Exploited CVEs: Daemon Tools Lite, TanStack, Nx Console</title><link>https://runtimerebel.com/blog/actively-exploited-cves-daemon-tools-lite-tanstack-nx-console</link><guid isPermaLink="true">https://runtimerebel.com/blog/actively-exploited-cves-daemon-tools-lite-tanstack-nx-console</guid><description>CISA added three vulnerabilities—CVE-2026-8398, CVE-2026-45321, CVE-2026-48027—to its KEV Catalog due to active exploitation. Prioritize patching.</description><pubDate>Wed, 27 May 2026 20:48:50 GMT</pubDate><category>CVE-2026-8398</category><category>CVE-2026-45321</category><category>CVE-2026-48027</category><category>CISA KEV</category><category>Daemon Tools Lite</category><category>TanStack</category><category>Nx Console</category><category>Embedded Malicious Code</category></item><item><title>CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw</title><link>https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</guid><description>CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.</description><pubDate>Wed, 27 May 2026 13:21:58 GMT</pubDate><category>CVE-2024-50498</category><category>cPanel</category><category>LiteSpeed</category><category>CISA KEV</category><category>XSS</category></item><item><title>CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day</title><link>https://runtimerebel.com/blog/cve-2024-50498-patch-exploited-litespeed-cpanel-plugin-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-patch-exploited-litespeed-cpanel-plugin-zero-day</guid><description>CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.</description><pubDate>Wed, 27 May 2026 09:17:56 GMT</pubDate><category>CVE-2024-50498</category><category>LiteSpeed</category><category>cPanel</category><category>CISA KEV</category><category>RCE</category><category>Privilege Escalation</category></item></channel></rss>