The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding five new security flaws that are currently under active exploitation. The vulnerabilities include CVE-2021-21311 affecting Adminer, CVE-2025-20352 impacting Cisco IOS and IOS XE, CVE-2025-10035 in Fortra GoAnywhere MFT, CVE-2025-59689 in Libraesva Email Security Gateway, and CVE-2025-32463 in Sudo. The Adminer flaw is a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to manipulate URL parameters, potentially enabling unauthorized access to internal resources and facilitating lateral movement within networks. The Cisco IOS and IOS XE vulnerability is a stack-based buffer overflow in the SNMP subsystem, which can be exploited by sending crafted SNMP packets, leading to denial of service or remote code execution as root, depending on attacker privileges. Fortra GoAnywhere MFT is affected by a critical deserialization vulnerability in its License Servlet, which could allow attackers to execute arbitrary code. Libraesva ESG suffers from a command injection vulnerability, and Sudo is impacted by a flaw involving the inclusion of functionality from an untrusted control sphere. CISA’s Product Security Incident Response Team (PSIRT) has confirmed that these vulnerabilities are being actively exploited in the wild. The addition of these flaws to the KEV Catalog is based on credible evidence of exploitation, and CISA has issued a Binding Operational Directive (BOD) 22-01 requiring Federal Civilian Executive Branch (FCEB) agencies to remediate these vulnerabilities by specified deadlines. The directive aims to reduce significant risk to federal networks, but CISA also strongly urges all organizations, not just federal agencies, to prioritize remediation of these vulnerabilities as part of their vulnerability management programs. The vulnerabilities span a range of critical systems, including database management tools, network operating systems, email security gateways, and managed file transfer platforms, highlighting the broad attack surface targeted by malicious actors. The Adminer SSRF vulnerability, with a CVSS score of 7.2, affects versions 4.0.0 to just before 4.7.9, while the Cisco IOS/IOS XE flaw, with a CVSS score of 7.7, impacts all devices with SNMP enabled. The Fortra GoAnywhere MFT vulnerability is rated as critical with a CVSS score of 10.0, underscoring the urgency of remediation. CISA’s ongoing updates to the KEV Catalog reflect the evolving threat landscape and the need for organizations to remain vigilant against actively exploited vulnerabilities. Organizations are encouraged to consult the KEV Catalog regularly and implement timely patches to mitigate the risk of compromise. The inclusion of these vulnerabilities in the KEV Catalog serves as a warning to both public and private sector entities about the heightened risk posed by these flaws. Failure to address these vulnerabilities could result in significant operational disruptions or unauthorized access to sensitive systems. CISA’s alert emphasizes the importance of proactive vulnerability management and cross-sector collaboration to defend against active cyber threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CISA flagged four additional security vulnerabilities as actively exploited and added them to its Known Exploited Vulnerabilities Catalog. As with other KEV updates, the action signals required remediation timelines for federal agencies and broader patching urgency for defenders.
CISA added five vulnerabilities affecting Adminer, Cisco IOS/IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and Sudo to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The agency said Federal Civilian Executive Branch agencies must remediate them by the specified BOD 22-01 deadlines and urged all organizations to prioritize patching.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcethecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.