#cisakev

8 posts · Last used 3d

Back to Timeline
Suriq - Always on Watch @suriq@infosec.exchange · 3d ago
🔴 EXPLOITED Check Point's SmartConsole flaw (CVE-2026-16232) lets an unauthenticated attacker log in as full admin. It is being exploited now. Affects Security Management servers reachable over the network. Fix: limit management access to your admin IPs, then patch. https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited #CVE #Phishing #CISAKEV #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 4d ago
Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours. All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned. #SharePoint #infosec https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys #CVE #Detection #CISAKEV #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 4d ago
Langflow's 'validate' endpoint just produced its SECOND unauthenticated root RCE in 14 months. CVE-2026-0770, CVSS 9.8, now in CISA's KEV list with a 3-day federal deadline. 220+ exploit attempts already logged. Patch, then pull it off the internet. https://suriq.io/blog/langflow-cve-2026-0770-validate-rce-kev #CVE #CISAKEV #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 14, 2026
🔴 EXPLOITED Two of Microsoft's three July zero-days were already being exploited when the patch shipped: an on-prem SharePoint bug and an AD FS privilege flaw. Both found by incident-response teams. Both on CISA's must-patch list. SharePoint due July 17, AD FS July 28. https://suriq.io/blog/microsoft-patch-tuesday-zero-days-exploited #CVE #Windows #CISAKEV #infosec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 13, 2026
Our weekly CVE report: 1,571 new flaws and 6 actively exploited vulnerabilities hit CISA KEV, including ColdFusion and Joomla RCE. #CVE #CISAKEV #Vulnerability #InfoSec #CyberSecurity https://securityonline.info/weekly-cve-report-2026-07-06/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 08, 2026
🔴 EXPLOITED Two Joomla page builders have CVSS-10 flaws that let anyone upload a webshell with no login: SP Page Builder and Page Builder CK. Both are exploited and on CISA's KEV list. Patch, then hunt: the fix won't remove the rogue admin it leaves behind. https://suriq.io/blog/joomla-page-builder-uploads-exploited-kev #CVE #CISAKEV #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 02, 2026
🔴 EXPLOITED Microsoft rated a SharePoint Server flaw (CVE-2026-45659, CVSS 8.8) unlikely to be exploited. It is being exploited. CISA added it to its must-patch list July 1. Run on-prem SharePoint? Install the May update now. https://suriq.io/blog/sharepoint-cve-2026-45659-kev-exploited #CVE #Detection #CISAKEV #infosec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 02, 2026
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now. #SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability https://securityonline.info/sharepoint-vulnerability-cve-2026-45659/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts