Skip to content
Threat Feed

Tag

Cisa-Kev

9 briefs RSS
high threat

CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog

CISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.

exploited Linux Kernel +1 vulnerability-management linux kernel cisa-kev
2c
high threat

Active Exploitation of Google Pixel Improper Authorization Vulnerability

CISA has added CVE-2026-58704, an improper authorization vulnerability in Google Pixel devices, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.

exploited Pixel vulnerability cisa-kev mobile-security
1c
critical threat

Active Exploitation of Cisco Secure Email Gateway SQL Injection

CISA has added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of a SQL injection vulnerability in Cisco Secure Email Gateway.

exploited Secure Email Gateway vulnerability cve sql-injection cisa-kev
1c
critical advisory

SQL Injection Vulnerability in Sangoma Switchvox

Sangoma Switchvox is vulnerable to an unauthenticated SQL injection flaw that allows remote attackers to execute arbitrary SQL commands on the backend PostgreSQL database, potentially leading to remote code execution.

Switchvox +1 webserver sql-injection vulnerability cisa-kev
2t 1c updated
low advisory

CVE-2026-66384 - Improper Path Limitation in JFrog Artifactory

JFrog Artifactory suffers from a path traversal vulnerability that allows an authenticated user to write files to unauthorized locations on the server by manipulating remote-repository configurations.

Artifactory vulnerability path-traversal cisa-kev jfrog
1t 1c
high threat

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.

exploited PoC SMA1000 Appliances +6 ssrf vulnerability cisa-kev remote-code-execution network-appliance
2t 2c 6i updated
critical threat

CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE

A critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.

exploited Forms vulnerability web-vulnerability rce file-upload cisa-kev
1r 2t 1c
critical threat

CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted File Upload leading to RCE

A critical unrestricted file upload vulnerability, CVE-2026-48908, in JoomShaper SP Page Builder allows unauthenticated attackers to upload arbitrary files of dangerous types, specifically PHP code, which can be executed on the server to achieve remote code execution and full system compromise.

SP Page Builder +1 web-exploit cve rce php cisa-kev
2r 3t 1i updated
critical advisory

Active Exploitation of SharePoint Deserialization Vulnerability (CVE-2026-20963)

CVE-2026-20963, a SharePoint deserialization vulnerability, is under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, requiring immediate patching and auditing of potentially compromised data.

CVE-2026-20963 sharepoint deserialization cisa-kev
2r 1t