Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Propelling manufacturing, aerospace and defence innovation through applied research

CISA adds 8 exploited flaws to KEV, sets federal deadline for April-May 2026

UK HPC data center reduces emissions by 75% with renewable energy

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds 8 exploited flaws to KEV, sets federal deadline for April-May 2026
Identity

CISA adds 8 exploited flaws to KEV, sets federal deadline for April-May 2026

By April 21, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 21, 2026Network security/threat intelligence

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known and Exploited Vulnerabilities (KEV) catalog, including three flaws affecting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation.

Here is the list of vulnerabilities:

CVE-2023-27351 (CVSS Score: 8.2) – An improper authentication vulnerability in PaperCut NG/MF could allow an attacker to bypass authentication on an affected installation via the SecurityRequestFilter class. CVE-2024-27199 (CVSS score: 7.3) – Relative path traversal vulnerability in JetBrains TeamCity could allow an attacker to perform limited administrative actions. CVE-2025-2749 (CVSS Score: 7.2) – Path traversal vulnerability in Kentico Xperience could allow an authenticated user’s staging sync server to upload arbitrary data to a relative location in the path. CVE-2025-32975 (CVSS Score: 10.0) – An improper authentication vulnerability in the Quest KACE Systems Management Appliance (SMA) could allow an attacker to impersonate a legitimate user without valid credentials. CVE-2025-48700 (CVSS Score: 6.1) – Cross-site scripting vulnerability in Synacor Zimbra Collaboration Suite (ZCS) could allow an attacker to execute arbitrary JavaScript within a user’s session and gain unauthorized access to sensitive information. CVE-2026-20122 (CVSS Score: 5.4) – An incorrect use of a vulnerability in the privileged API of Cisco Catalyst SD-WAN Manager could allow an attacker to upload and overwrite arbitrary files on an affected system and gain vmanage user privileges. CVE-2026-20128 (CVSS Score: 7.5) – A recoverable password storage vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges by accessing the DCA user credentials file on the file system as a low-privileged user. CVE-2026-20133 (CVSS Score: 6.5) – An unauthorized actor vulnerability in Cisco Catalyst SD-WAN Manager could lead to sensitive information disclosure and allow a remote attacker to view sensitive information on an affected system.

It is worth noting that CISA added CVE-2024-27198, another flaw affecting on-premises versions of JetBrains TeamCity, to the KEV catalog in March 2024. It is currently unclear whether both vulnerabilities are being exploited together and whether the activity is the work of the same threat actor.

Meanwhile, the CVE-2023-27351 exploit is believed to have been launched by Race Tempest in April 2023 in conjunction with attacks delivering the Cl0p and LockBit ransomware families.

Regarding CVE-2025-32975, Arctic Wolf said late last month that it observed unknown attackers weaponizing this bug to target unpatched SMA systems, but the exact end goal of the campaign was unknown.

Cisco also said it became aware of the CVE-2026-20122 and CVE-2026-20128 exploits in March 2026. The company has not yet revised its advisory to reflect the exploitation of CVE-2026-20133 in the wild.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to address three Cisco vulnerabilities by April 23, 2026, and the remaining vulnerabilities by May 4, 2026.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUK HPC data center reduces emissions by 75% with renewable energy
Next Article Propelling manufacturing, aerospace and defence innovation through applied research

Related Posts

SGLang CVE-2026-5760 (CVSS 9.8) enables RCE via a malicious GGUF model file

April 20, 2026

Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

April 20, 2026

Why most AI deployments stop after the demo

April 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Propelling manufacturing, aerospace and defence innovation through applied research

CISA adds 8 exploited flaws to KEV, sets federal deadline for April-May 2026

UK HPC data center reduces emissions by 75% with renewable energy

Who is the next Apple CEO John Ternus?

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.