Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Water monitoring finds UK chemicals permanently reduced

CISA, SolarWinds, Ivanti, Workspace One vulnerabilities reported as being actively exploited

Founders Fund is nearing a $6 billion offering for its latest growth fund, sources say

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA, SolarWinds, Ivanti, Workspace One vulnerabilities reported as being actively exploited
Identity

CISA, SolarWinds, Ivanti, Workspace One vulnerabilities reported as being actively exploited

userBy userMarch 10, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 10, 2026Vulnerabilities / Enterprise Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation.

The vulnerability list is as follows:

CVE-2021-22054 (CVSS Score: 7.5) – A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) could allow a malicious attacker with network access to UEM to send requests without authentication and access sensitive information. CVE-2025-26399 (CVSS Score: 9.8) – Deserialization untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk could allow an attacker to execute commands on the host machine. CVE-2026-1603 (CVSS Score: 8.6) – Authentication bypass using an alternate path or channel vulnerability in Ivanti Endpoint Manager could allow a remote, unauthenticated attacker to disclose certain stored credential data.

The addition of CVE-2025-26399 follows reports from Microsoft and Huntress that threat actors are exploiting security flaws in the SolarWinds Web Help Desk to gain initial access. This activity is believed to be the work of the Warlock ransomware team.

Meanwhile, CVE-2021-22054 was reported by GreyNoise in March 2025 as being exploited along with several other SSRF vulnerabilities in other products as part of a coordinated campaign.

At this time, details about how CVE-2026-1603 is actually weaponized are unknown. At the time of writing, Ivanti’s security bulletin has not been updated to reflect the exploit.

To combat the risks posed by active threats, Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply patches to the SolarWinds Web Help Desk by March 12, 2026, and two others by March 23, 2026.

“These types of vulnerabilities are frequent attack vectors for malicious cyber attackers and pose significant risks to federal enterprises,” CISA said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFounders Fund is nearing a $6 billion offering for its latest growth fund, sources say
Next Article Water monitoring finds UK chemicals permanently reduced
user
  • Website

Related Posts

Malicious npm package disguised as OpenClaw installer deploys RAT and steals macOS credentials

March 9, 2026

UNC4899 Developer compromises encryption company after airdropping Trojanized files onto work devices

March 9, 2026

Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

March 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Water monitoring finds UK chemicals permanently reduced

CISA, SolarWinds, Ivanti, Workspace One vulnerabilities reported as being actively exploited

Founders Fund is nearing a $6 billion offering for its latest growth fund, sources say

Electric air taxis are about to start operating in 26 states.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.