Active exploitation News
A vulnerability that attackers are already using against real systems, not just one that could be exploited in theory.
All active exploitation news
-
ACTIVE EXPLOITATIONExploited Zammad helpdesk chain runs from session hijack to root
CISA added two chained Zammad flaws to its KEV catalog: a session hijack giving code execution and a local root escalation, with a 5 October federal deadline.
-
ACTIVE EXPLOITATIONExploited FortiMail flaw lets attackers write files with no fix out yet
CISA added an unauthenticated FortiMail path traversal to its KEV catalog with a three-day deadline and a compromise check, while fixed builds are still pending.
-
ACTIVE EXPLOITATIONApple CoreGraphics zero-day exploited in targeted attacks, CISA says
CISA added an Apple CoreGraphics memory flaw to its KEV catalog after reports of targeted attacks, with a 2 October deadline and forensic triage for iOS and macOS.
-
ACTIVE EXPLOITATIONExploited Cisco SD-WAN Manager flaw gives attackers admin API access
CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass to its KEV catalog with a three-day federal deadline and a required compromise check.
-
ACTIVE EXPLOITATIONTwo Citrix NetScaler zero-days under active attack, CISA and NCSC warn
CISA and the UK NCSC confirm attackers are exploiting two critical NetScaler ADC and Gateway flaws as zero-days. Check for compromise, then patch by 30 September.
-
ACTIVE EXPLOITATIONCISA confirms exploitation of SharePoint and MikroTik RouterOS flaws
CISA added a SharePoint code injection flaw and a MikroTik RouterOS SSH bug that completes a known router takeover chain to KEV, with a 28 September deadline.
-
ACTIVE EXPLOITATIONCISA flags six exploited flaws in VPN, SD-WAN and commerce platforms
CISA added six actively exploited CVEs in Check Point, F5 BIG-IP APM, Arista VeloCloud, WSO2 and Adobe Commerce to KEV this week, with deadlines of 25 and 27 September.
-
ACTIVE EXPLOITATIONCISA confirms attacks on WordPress core file inclusion flaw
CISA added a WordPress core file inclusion bug that can lead to code execution to its KEV catalog, set a three-day federal deadline and required forensic triage.