🔴 EXPLOITED
CVE-2025-25249: A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthorized code execution via crafted packets. It is listed in CISA KEV.
Affected: FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 and 7.2 branches.
Fix: upgrade to the patched releases. CISA due date September 12, 2026.
https://www.cve.org/CVERecord?id=CVE-2025-25249
#CISAKEV #infosec #cybersecurity
About This Hashtag
#cisakev
13 posts
Last used 5d
#cisakev
13 posts· Last used 5d
This weekly CVE report covers 1,877 new CVEs and 6 actively exploited flaws added to CISA KEV, including N-able, TeamCity, and Langflow bugs.
#CVE #CISAKEV #VulnerabilityManagement #InfoSec #PatchNow #CyberSecurity
https://securityonline.info/weekly-cve-report-august-2026/?utm_source=mastodon&utm_medium=jetpack_social
🤖 CVE-2026-20316 (KEV): Cisco FMC zero-day actively exploited. Unauthenticated attacker can access devices via static credentials. Added to CISA KEV — federal agencies must remediate by Aug 19.
🔗 https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
#CVE #Cisco #ZeroDay #CISAKEV #CyberSec
🔴 EXPLOITED
Cisco Secure Firewall Management Center ships a hardcoded password that lets a stranger log in with no credentials (CVE-2026-20316).
It is being exploited now and sits on CISA's must-patch list.
Apply the hotfix, then check logs for signs of entry.
https://suriq.io/blog/cisco-fmc-hardcoded-password-cve-2026-20316
#CVE #Detection #CISAKEV #infosec
🔴 EXPLOITED
CISA just flagged a Fortinet firewall flaw as actively exploited.
CVE-2025-68686 bypasses the fix meant to kick attackers out of hacked FortiGates. They keep reading the device's files.
Patch FortiOS to 7.6.2 or 7.4.7, then rotate secrets.
https://suriq.io/blog/fortios-symlink-patch-bypass-cve-2025-68686-kev
#CISAKEV #infosec #cybersecurity
🔴 EXPLOITED
Check Point's SmartConsole flaw (CVE-2026-16232) lets an unauthenticated attacker log in as full admin. It is being exploited now.
Affects Security Management servers reachable over the network.
Fix: limit management access to your admin IPs, then patch.
https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited
#CVE #Phishing #CISAKEV #infosec
Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours.
All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned.
#SharePoint #infosec
https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys
#CVE #Detection #CISAKEV #infosec
Langflow's 'validate' endpoint just produced its SECOND unauthenticated root RCE in 14 months. CVE-2026-0770, CVSS 9.8, now in CISA's KEV list with a 3-day federal deadline. 220+ exploit attempts already logged. Patch, then pull it off the internet.
https://suriq.io/blog/langflow-cve-2026-0770-validate-rce-kev
#CVE #CISAKEV #infosec #cybersecurity
🔴 EXPLOITED
Two of Microsoft's three July zero-days were already being exploited when the patch shipped: an on-prem SharePoint bug and an AD FS privilege flaw.
Both found by incident-response teams. Both on CISA's must-patch list.
SharePoint due July 17, AD FS July 28.
https://suriq.io/blog/microsoft-patch-tuesday-zero-days-exploited
#CVE #Windows #CISAKEV #infosec
Our weekly CVE report: 1,571 new flaws and 6 actively exploited vulnerabilities hit CISA KEV, including ColdFusion and Joomla RCE.
#CVE #CISAKEV #Vulnerability #InfoSec #CyberSecurity
https://securityonline.info/weekly-cve-report-2026-07-06/?utm_source=mastodon&utm_medium=jetpack_social
🔴 EXPLOITED
Two Joomla page builders have CVSS-10 flaws that let anyone upload a webshell with no login: SP Page Builder and Page Builder CK.
Both are exploited and on CISA's KEV list.
Patch, then hunt: the fix won't remove the rogue admin it leaves behind.
https://suriq.io/blog/joomla-page-builder-uploads-exploited-kev
#CVE #CISAKEV #infosec #cybersecurity
🔴 EXPLOITED
Microsoft rated a SharePoint Server flaw (CVE-2026-45659, CVSS 8.8) unlikely to be exploited. It is being exploited.
CISA added it to its must-patch list July 1.
Run on-prem SharePoint? Install the May update now.
https://suriq.io/blog/sharepoint-cve-2026-45659-kev-exploited
#CVE #Detection #CISAKEV #infosec
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now.
#SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability
https://securityonline.info/sharepoint-vulnerability-cve-2026-45659/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts