CISA has updated its Known Exploited Vulnerabilities (KEV) catalog with several critical entries across software ecosystems including ownCloud, Microsoft, Red Hat, and the Linux kernel. These additions highlight active adversary targeting of perimeter services, local privilege escalation flaws, and remote authentication bypasses. Security operations and infrastructure teams should prioritize immediate validation, emergency patching, and log hunting across all affected assets.
Reading time 10 minutes
CISA added three new entries to its Known Exploited Vulnerabilities (KEV) catalog this week: CVE-2026-20349 (Cisco ASA and FTD Heap Inspection DoS), CVE-2026-68820 (Microsoft Windows WinSock AFD.sys Use-After-Free LPE), and CVE-2026-72898 (Metabase Unauthenticated SQL Injection Admin Takeover). These additions emphasize continued adversary focus on perimeter SSL VPN gateways, active kernel-level privilege escalation zero-days utilized by nation-state actors, and unauthenticated zero-day takeovers of business intelligence software holding stored data warehouse credentials. Security operations and infrastructure teams should prioritize immediate validation, emergency patching, and log hunting across these assets.
Reading time 10 minutes
CISA added six new entries to its Known Exploited Vulnerabilities (KEV) catalog this week: CVE-2026-8037 (Progress LoadMaster Command Injection), CVE-2026-63077 (JetBrains TeamCity Deserialization RCE), CVE-2026-18556 and CVE-2026-18577 (N-able N-central Authentication Bypasses), CVE-2026-34486 (Apache Tomcat EncryptInterceptor Bypass), and CVE-2026-9198 (IBM Langflow Unauthenticated Code Injection). These additions highlight heightened adversary targeting of tier-0 management interfaces, remote monitoring platforms (RMM), continuous integration/continuous delivery (CI/CD) pipelines, and AI orchestrators. Organizations operating these services must apply official vendor updates immediately to secure their perimeter and internal supply chains
Reading time 10 minutes
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.