Adobe ColdFusion leads seven CVEs now confirmed exploited
Seven flaws are now confirmed exploited: an Adobe ColdFusion path traversal and a wave of Joomla file-upload RCEs, all on CISA KEV this week. Patch by exposure first.
Seven flaws are now confirmed exploited: an Adobe ColdFusion path traversal and a wave of Joomla file-upload RCEs, all on CISA KEV this week. Patch by exposure first.
Two flaws are now confirmed exploited: a Microsoft SharePoint code-execution bug and a SimpleHelp auth bypass, both on CISA KEV this week. Patch them before your CVSS queue.
A practical guide to check if your company credentials leaked: where stolen logins come from, how to search breach and infostealer data safely, and what to do about a hit.
CVE-2026-45659 is an actively exploited deserialization flaw in Microsoft SharePoint Server. CISA added it to KEV on July 1 with a federal deadline of July 4, 2026.
CVE-2026-48558, a CVSS 10 authentication bypass in SimpleHelp, is actively exploited and added to CISA KEV with a July 2 federal patch deadline.
Four flaws now confirmed exploited, added to CISA's KEV the week of June 29, 2026: Cisco Unified CM, Ubiquiti UniFi OS, PTC Windchill and Lantronix. What to patch first.
CVE-2026-20230 is a server-side request forgery flaw in Cisco Unified CM and Unified CM SME added to CISA KEV on June 25. Federal deadline is June 28.
Is penetration testing required for SOC 2? Not by name in the Trust Services Criteria, but auditors expect one to satisfy CC7.1. What to test, and how often.
Ubiquiti UniFi OS and Lantronix EDS5000 reached CISA KEV on June 23 with unauthenticated root flaws, and Copy Fail (CVE-2026-31431) now hits B&R OT gear. Patch fast.
Three flaws now confirmed exploited, added to CISA's KEV the week of June 22, 2026: Splunk Enterprise, the Joomla JCE editor and a LiteSpeed cPanel plugin. What to patch first.
A leaked dataset exposed plaintext VPN credentials for 73,932 FortiGate firewalls in 194 countries. What FortiBleed is, whether your gateway is affected, and what to do now.
CISA added Splunk Enterprise CVE-2026-20253 to KEV on June 18, 2026. Unauthenticated file write via PostgreSQL sidecar, federal due date June 21. Who is affected and what to do.
Vulnerability scanning vs penetration testing: one finds known flaws at scale, the other proves what an attacker can exploit. Which you need, and why both.
CVE-2026-48907 in Joomla Content Editor lets unauthenticated attackers upload PHP webshells. CISA added it to KEV on June 16; patch to JCE 2.9.99.6 now.
Attackers are exploiting Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and the LiteSpeed cPanel plugin (CVE-2026-54420), both added to CISA KEV on June 15, 2026. Patch now.
CISA added six CVEs to KEV in the week of June 15, 2026: Oracle PeopleSoft, Ivanti Sentry, Cisco SD-WAN, Arista, Chrome and LiteLLM. Scores and what to patch first.
Oracle PeopleSoft PeopleTools CVE-2026-35273: active exploitation, known ransomware use, unauthenticated takeover, CVSS 9.8, on CISA KEV. Who is affected and what to do.
CISA added Ivanti Sentry CVE-2026-10520 to KEV on June 11, 2026. Unauthenticated root RCE, CVSS 10.0, federal due date June 14. Here is who is affected and what to do.
What a CVE is, who assigns the IDs, how the numbering works, and how to act on the 40,000+ published each year. A plain-language guide for IT and security teams.
Four CVEs hit CISA KEV this week: Linux, Android, Magento RCE, and SolarWinds DoS. See which patch cuts the most risk against confirmed exploitation.
CVSS vs EPSS vs KEV: three signals that rank vulnerabilities differently. Why CloudKey patches KEV-listed CVEs first, EPSS-elevated next, CVSS last.
Ce site est aussi disponible en français.