Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogwidely-deployed-product-advisoryendpoint-software-vulnerability

CISA Adds Actively Exploited Vulnerabilities to the Known Exploited Vulnerabilities Catalog

Updated 6h agoFirst seen Mar 11, 202660 sources

CISA updated its Known Exploited Vulnerabilities (KEV) Catalog after identifying evidence of active exploitation in the wild, reinforcing that organizations should prioritize remediation under BOD 22-01 timelines (for FCEB agencies) and as a broader risk-reduction measure for all enterprises. One update added CVE-2025-68613 affecting n8n, described as an improper control of dynamically-managed code resources issue, and CISA emphasized that KEV entries represent vulnerabilities being leveraged by threat actors.

Separate KEV-related reporting described additional catalog additions tied to active exploitation, including CVE-2026-1603 (Ivanti Endpoint Manager) described as an authentication bypass with potential exposure of credential data (fixed in EPM 2024 SU5), CVE-2025-26399 (SolarWinds Web Help Desk) described as a critical deserialization/RCE issue in AjaxProxy (fixed in WHD 12.8.7 HF1), and CVE-2021-22054 (Omnissa/VMware Workspace ONE) described as an SSRF. Additional coverage also highlighted CISA’s KEV addition of multiple Apple vulnerabilities—CVE-2023-43000, CVE-2023-41974 (both use-after-free), and CVE-2021-30952 (integer overflow)—impacting macOS/iOS/iPadOS and related platforms, with exploitation reported as active and patching urged to reduce risk of arbitrary code execution and elevated privileges.

Share:
CISA Adds Actively Exploited Vulnerabilities to the Known Exploited Vulnerabilities Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

47 events from the most recent confirmed update back to the earliest known activity.

47 EVENTS
Jun 5, 20261d ago

CISA adds SolarWinds Serv-U flaw CVE-2026-28318 to KEV

On 2026-06-05, CISA added CVE-2026-28318, an uncontrolled resource consumption vulnerability affecting SolarWinds Serv-U, to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation. CISA said this vulnerability class is a frequent attack vector for malicious cyber actors and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Jun 3, 20263d ago

CISA adds Mirasvit Full Page Cache Warmer flaw CVE-2026-45247 to KEV

On 2026-06-03, CISA added CVE-2026-45247, a deserialization of untrusted data vulnerability affecting Mirasvit Full Page Cache Warmer, to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation. CISA said this vulnerability class is a common attack vector for malicious cyber actors and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Jun 2, 20264d ago

CISA adds two known exploited vulnerabilities to KEV catalog

On 2026-06-02, CISA published an alert stating it added two vulnerabilities to its Known Exploited Vulnerabilities catalog. The provided reference does not include the substantive advisory details, so the specific CVEs, affected products, and remediation deadlines are not visible.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA

CISA adds Linux kernel and Android Framework flaws to KEV

On 2026-06-02, CISA added CVE-2022-0492 in the Linux kernel and CVE-2025-48595 in Android Framework to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. CISA directed Federal Civilian Executive Branch agencies to remediate the flaws by 2026-06-05, and the reference notes Google addressed the Android issue in its June 2026 Android security patches.

CISA Adds Actively Exploited Vulnerabilities to KEV
Jun 1, 20265d ago

CISA adds Oracle WebLogic flaw CVE-2024-21182 to KEV

On 2026-06-01, CISA added CVE-2024-21182, a vulnerability affecting Oracle WebLogic Server, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. CISA said this vulnerability class is a frequent attack vector for malicious cyber actors and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 29, 20268d ago

CISA adds Palo Alto PAN-OS flaw CVE-2026-0257 to KEV

On 2026-05-29, CISA added CVE-2026-0257, an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said this vulnerability class is a common attack vector that poses significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 27, 202610d ago

CISA adds three new vulnerabilities to KEV catalog

On 2026-05-27, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-8398 in Daemon Tools Lite, CVE-2026-45321 in TanStack, and CVE-2026-48027 in Nx Console. CISA said the flaws were actively exploited and required remediation under Binding Operational Directive 22-01.

CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA
May 26, 202611d ago

CISA adds LiteSpeed cPanel Plugin flaw CVE-2026-48172 to KEV

On 2026-05-26, CISA added CVE-2026-48172, a privilege escalation vulnerability affecting the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said this vulnerability class is a common attack vector that poses significant risk to the federal enterprise and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 21, 202616d ago

CISA adds Langflow and Trend Micro Apex One flaws to KEV

On 2026-05-21, CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-34291, a Langflow origin validation error vulnerability, and CVE-2026-34926, a Trend Micro Apex One (On-Premise) directory traversal vulnerability. CISA said both were actively exploited and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
May 20, 202617d ago

CISA adds seven new vulnerabilities to KEV catalog

On 2026-05-20, CISA added seven vulnerabilities affecting Microsoft Windows, Microsoft DirectX, Adobe Acrobat and Reader, Microsoft Internet Explorer, and Microsoft Defender to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaws, including legacy issues from 2008–2010 and two newer 2026 Microsoft Defender vulnerabilities, are common attack vectors that pose significant risk to the federal enterprise and require remediation under BOD 22-01.

CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA
May 15, 202622d ago

CISA adds Microsoft Exchange Server flaw CVE-2026-42897 to KEV

On 2026-05-15, CISA added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said this vulnerability class is a common attack vector that poses significant risk to the federal enterprise and urged timely remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 8, 202629d ago

CISA adds BerriAI LiteLLM flaw CVE-2026-42208 to KEV

On 2026-05-08, CISA added CVE-2026-42208, a SQL injection vulnerability affecting BerriAI LiteLLM, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said this vulnerability class is a common attack vector that poses significant risk to the federal enterprise and urged timely remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 7, 20261mo ago

CISA adds Ivanti EPMM flaw CVE-2026-6973 to KEV

On 2026-05-07, CISA added CVE-2026-6973, an improper input validation vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 1, 20261mo ago

CISA adds Linux Kernel flaw CVE-2026-31431 to KEV

On 2026-05-01, CISA added CVE-2026-31431, an incorrect resource transfer between spheres vulnerability in the Linux Kernel, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said vulnerabilities of this type are frequently used by malicious cyber actors, pose significant risk to the federal enterprise, and should be prioritized for remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 24, 20261mo ago

CISA adds four new vulnerabilities to KEV catalog

On 2026-04-24, CISA added four vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and the D-Link DIR-823X to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the path traversal, missing authorization, and command injection flaws are common attack vectors that pose significant risk to the federal enterprise and urged timely remediation under BOD 22-01.

CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA
Apr 23, 20261mo ago

CISA adds Marimo flaw CVE-2026-39987 to KEV

On 2026-04-23, CISA added CVE-2026-39987, a remote code execution vulnerability affecting Marimo, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 22, 20262mo ago

CISA adds Microsoft Defender flaw CVE-2026-33825 to KEV

On 2026-04-22, CISA added CVE-2026-33825, an insufficient granularity of access control vulnerability affecting Microsoft Defender, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 20, 20262mo ago

CISA adds eight new vulnerabilities to KEV catalog

On 2026-04-20, CISA added eight vulnerabilities affecting PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra Collaboration Suite, and Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaws are common attack vectors that pose significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds Eight Known Exploited Vulnerabilities to Catalog | CISA
Apr 16, 20262mo ago

CISA adds Apache ActiveMQ flaw CVE-2026-34197 to KEV

On 2026-04-16, CISA added CVE-2026-34197, an improper input validation vulnerability affecting Apache ActiveMQ, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged timely remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 14, 20262mo ago

CISA adds Microsoft Office and SharePoint flaws to KEV

On 2026-04-14, CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2009-0238, a Microsoft Office remote code execution flaw, and CVE-2026-32201, an improper input validation vulnerability in Microsoft SharePoint Server. CISA said both were actively exploited and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
Apr 13, 20262mo ago

CISA adds seven new vulnerabilities to KEV catalog

On 2026-04-13, CISA added seven vulnerabilities affecting Microsoft Visual Basic for Applications, Adobe Acrobat, Microsoft Exchange Server, Microsoft Windows, Fortinet products, and Adobe Acrobat and Reader to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaws are common attack vectors that pose significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA
Apr 8, 20262mo ago

CISA adds Ivanti EPMM flaw CVE-2026-1340 to KEV

On 2026-04-08, CISA added CVE-2026-1340, a code injection vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw presents significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 6, 20262mo ago

CISA adds Fortinet FortiClient EMS flaw CVE-2026-35616 to KEV

On 2026-04-06, CISA added CVE-2026-35616, an improper access control vulnerability affecting Fortinet FortiClient EMS, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw presents significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 1, 20262mo ago

CISA adds Google Dawn flaw CVE-2026-5281 to KEV

On 2026-04-01, CISA added CVE-2026-5281, a Google Dawn use-after-free vulnerability, to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 27, 20262mo ago

CISA adds F5 BIG-IP flaw CVE-2025-53521 to KEV

On 2026-03-27, CISA added CVE-2025-53521, a remote code execution vulnerability affecting F5 BIG-IP, to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation. CISA warned the flaw poses significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 26, 20262mo ago

CISA adds Aqua Security Trivy flaw CVE-2026-33634 to KEV

On 2026-03-26, CISA added CVE-2026-33634, an Aqua Security Trivy Embedded Malicious Code vulnerability, to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation. CISA said the flaw is a frequent attack vector that poses significant risk to the federal enterprise and urged prioritized remediation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 25, 20262mo ago

CISA adds Langflow code injection flaw CVE-2026-33017 to KEV

On 2026-03-25, CISA added CVE-2026-33017, a code injection vulnerability affecting Langflow, to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation. CISA said the flaw poses significant risk to the federal enterprise and urged prioritized remediation under BOD 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 19, 20263mo ago

CISA adds Cisco firewall management flaw CVE-2026-20131 to KEV

On 2026-03-19, CISA added CVE-2026-20131, a deserialization of untrusted data vulnerability affecting Cisco Secure Firewall Management Center and Cisco Security Cloud Control Firewall Management, to the KEV catalog. CISA said the flaw was under active exploitation and posed significant risk to the federal enterprise.

Mar 18, 20263mo ago

CISA adds Synacor Zimbra XSS flaw CVE-2025-66376 to KEV

On 2026-03-18, CISA added CVE-2025-66376, a cross-site scripting vulnerability affecting Synacor Zimbra Collaboration Suite, to the KEV catalog. The agency said the flaw was actively exploited and should be prioritized for remediation.

Mar 16, 20263mo ago

CISA adds Wing FTP Server vulnerability CVE-2025-47813 to KEV

On 2026-03-16, CISA added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to the KEV catalog after evidence of active exploitation emerged. CISA warned that the issue presented significant risk to federal agencies and urged timely patching.

Mar 13, 20263mo ago

CISA adds Google Skia and Chromium V8 flaws to KEV

On 2026-03-13, CISA added CVE-2026-3909, a Google Skia out-of-bounds write vulnerability, and CVE-2026-3910, a Google Chromium V8 vulnerability, to the KEV catalog. The agency said both were being actively exploited and required prompt remediation.

Mar 11, 20263mo ago

CISA adds n8n vulnerability CVE-2025-68613 to KEV

On 2026-03-11, CISA added CVE-2025-68613, an improper control of dynamically managed code resources vulnerability affecting n8n, to the KEV catalog after evidence of active exploitation. CISA said the flaw posed significant risk to the federal enterprise and required remediation under BOD 22-01.

Mar 9, 20263mo ago

CISA adds Ivanti, SolarWinds, and Omnissa flaws to KEV catalog

By 2026-03-09, CISA had added three vulnerabilities to the KEV catalog based on active exploitation evidence: CVE-2026-1603 in Ivanti Endpoint Manager, CVE-2025-26399 in SolarWinds Web Help Desk, and CVE-2021-22054 in Omnissa Workspace ONE. The listed issues included authentication bypass, unauthenticated remote code execution, and SSRF risks.

Mar 5, 20263mo ago

CISA adds three Apple vulnerabilities to KEV catalog

On 2026-03-05, CISA added three actively exploited Apple vulnerabilities affecting macOS, iOS, iPadOS, Safari, and related platforms to its Known Exploited Vulnerabilities catalog. The flaws included two use-after-free issues and one integer overflow issue that could lead to memory corruption, arbitrary code execution, and in one case kernel-privileged code execution.

Jan 27, 20264mo ago

CISA adds one vulnerability to KEV catalog

On 2026-01-27, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicates CISA had evidence of active exploitation and urged remediation in line with KEV guidance.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 4, 20251y ago

CISA adds four known exploited vulnerabilities to KEV catalog

On 2025-03-04, CISA announced it had added four vulnerabilities to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency said the flaws posed significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA
Dec 19, 20241y ago

CISA adds one vulnerability to KEV catalog

On 2024-12-19, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicates CISA had evidence of active exploitation and urged remediation in line with KEV guidance.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Aug 15, 20242y ago

CISA adds one vulnerability to KEV catalog

On 2024-08-15, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicates CISA had evidence of active exploitation and urged remediation in line with KEV guidance.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Jul 17, 20242y ago

CISA adds three known exploited vulnerabilities to KEV catalog

On 2024-07-17, CISA announced it had added three vulnerabilities to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency said the flaws posed significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA
Feb 9, 20242y ago

CISA adds one vulnerability to KEV catalog

On 2024-02-09, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicated CISA had evidence of active exploitation and urged remediation in line with KEV guidance.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Jan 10, 20242y ago

CISA adds Microsoft SharePoint flaw CVE-2023-29357 to KEV

On 2024-01-10, CISA added CVE-2023-29357, a Microsoft SharePoint Server privilege escalation vulnerability, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. CISA said this vulnerability type is a common attack vector and urged timely remediation under Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Nov 14, 20233y ago

CISA adds three known exploited vulnerabilities to KEV catalog

On 2023-11-14, CISA announced it had added three vulnerabilities to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency said the flaws posed significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA
Nov 13, 20233y ago

CISA adds six known exploited vulnerabilities to KEV catalog

On 2023-11-13, CISA announced it had added six vulnerabilities to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency said the flaws posed significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA
Aug 21, 20233y ago

CISA adds one known exploited vulnerability to KEV catalog

On 2023-08-21, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicated CISA had evidence of active exploitation and urged remediation in line with Binding Operational Directive 22-01.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Sep 23, 20224y ago

CISA adds one known exploited vulnerability to KEV catalog

On 2022-09-23, CISA announced it had added one known exploited vulnerability to its Known Exploited Vulnerabilities catalog. The advisory indicated CISA had evidence of active exploitation and urged remediation in line with Binding Operational Directive 22-01.

CISA Has Added One Known Exploited Vulnerability to Catalog | CISA
Apr 11, 20224y ago

CISA adds eight known exploited vulnerabilities to KEV catalog

On 2022-04-11, CISA announced it had added eight vulnerabilities to its Known Exploited Vulnerabilities catalog after determining there was evidence of active exploitation. The agency said these flaws posed significant risk to the federal enterprise and urged prioritized remediation under Binding Operational Directive 22-01.

CISA Adds Eight Known Exploited Vulnerabilities to Catalog | CISA
Nov 3, 20215y ago

CISA orders federal agencies to remediate hundreds of exploited flaws

On 2021-11-03, CISA ordered U.S. federal civilian agencies to fix hundreds of known exploited security vulnerabilities under Binding Operational Directive 22-01. The action established remediation deadlines for vulnerabilities in CISA's Known Exploited Vulnerabilities catalog and marked an early major federal push to address actively abused flaws.

CISA orders federal agencies to fix hundreds of exploited security flaws
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

123 LINKEDOpen in app
Vulnerabilities
58 linked
Langflow chained account takeover and RCE via CORS origin validation errorMS08-067 Windows Server Service Buffer OverflowMicrosoft DirectX QuickTime Movie Parser Filter NULL Byte Overwrite RCEMicrosoft Internet Explorer HTML Object Memory Corruption Use-After-FreeHeap-Based Buffer Overflow in Adobe Acrobat and Reader via Crafted PDFMicrosoft Internet Explorer Peer Objects Use-After-Free RCEUnDefend - Microsoft Defender Denial of Service VulnerabilityRedSun - Microsoft Defender Link Following Local Privilege EscalationDirectory Traversal in Trend Micro Apex One (On-Premise)Authentication Bypass in PaperCut NG/MF SecurityRequestFilterAuthenticated Path Traversal and Arbitrary File Upload RCE in Kentico Xperience Staging Sync ServerVisual Basic for Applications Insecure Library Loading VulnerabilityApple Multiple Products Integer Overflow or Wraparound VulnerabilityIvanti EPMM Remote Unauthenticated API Access Authentication BypassOmnissa Workspace ONE UEM Server-Side Request ForgeryPath Traversal in Samsung MagicINFO 9 ServerPrivilege Escalation in Host Process for Windows TasksMicrosoft Exchange Server Deserialization of Untrusted Data RCESimpleHelp Missing Authorization Privilege EscalationUse-after-free RCE in Adobe AcrobatSimpleHelp Zip Slip Arbitrary File Upload Leading to RCEParallax kernel use-after-free in Apple iOS and iPadOSCommand Injection in D-Link DIR-823X /goform/set_prohibitingUnauthenticated AjaxProxy deserialization RCE in SolarWinds Web Help DeskUnauthenticated RCE in F5 BIG-IP APM access policy handlingAuthentication Bypass in Quest KACE Systems Management Appliance SSOSQL Injection RCE in Ivanti Endpoint Manager Core ServerWindows Common Log File System Driver Out-of-Bounds Read Privilege EscalationJetBrains TeamCity Relative Path Traversal Authentication BypassZero-click XSS in Zimbra Collaboration Classic UISolarWinds Web Help Desk AjaxProxy Java Deserialization RCEWebKit Use-After-Free in Apple Safari, iOS, iPadOS, and macOSUnauthenticated Java Deserialization RCE in SolarWinds Web Help Desk AjaxProxyRemote Code Execution in Microsoft Office Excel Malformed Object HandlingAuthenticated RCE in n8n Workflow Expression EvaluationStored XSS in Zimbra Collaboration Classic UI via CSS @import in HTML emailUnauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)Unauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)Unauthenticated SQL Injection RCE in Fortinet FortiClient EMSAuthentication Bypass in Ivanti Endpoint ManagerArbitrary File Overwrite in Cisco Catalyst SD-WAN Manager APICisco Catalyst SD-WAN Manager DCA credential disclosure / recoverable password vulnerabilitySensitive Information Exposure in Cisco Catalyst SD-WAN ManagerArbitrary code execution in Chrome V8 via crafted HTML pageOut-of-bounds write in Skia in Google ChromeUnauthenticated RCE in Langflow build_public_tmp endpointTrivy supply chain compromise via malicious release and retagged GitHub ActionsUse-After-Free in Google Chrome Dawn WebGPUAuthentication Bypass and RCE in Fortinet FortiClient EMSAuthenticated RCE in Apache ActiveMQ Classic Jolokia JMX-HTTP BridgePre-Auth RCE in Marimo /terminal/ws WebSocket EndpointAdobe Acrobat and Reader Prototype Pollution Arbitrary Code ExecutionBlueHammerMicrosoft SharePoint Server Spoofing VulnerabilityCopy Fail local privilege escalation in Linux kernel algif_aeadPre-auth SQL Injection in BerriAI LiteLLM Proxy API Key VerificationRemote Code Execution in Ivanti Endpoint Manager Mobile (EPMM)Microsoft Exchange Server OWA Reflected XSS Spoofing Vulnerability
Threat actors
2 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.