ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27351
Authentication Bypass in PaperCut NG/MF Print Management Software

CVE-2023-27351 is an improper authentication flaw (CWE-287) in the SecurityRequestFilter class of PaperCut NG and MF print management software, where the authentication algorithm is improperly implemented. A remote, unauthenticated attacker can trigger it over the network with no user interaction or special privileges to bypass authentication on the affected server (CVSS 3.1: 7.5). Once authentication is bypassed, the attacker gains access to the PaperCut system; in observed campaigns this access was leveraged to deliver Cl0p and LockBit ransomware, as confirmed by Microsoft. Organizations running PaperCut NG (version 22.0.5, Build 63914, is cited in the advisory) or PaperCut MF are affected. The flaw was exploited as a zero-day, is CISA KEV-listed (added 2026-04-20) with known ransomware use, and EPSS places the 30-day exploitation probability at 78.1%.

Do: Upgrade PaperCut NG/MF to the fixed release per the vendor's emergency patch advisory, first confirming the running build (NG 22.0.5, Build 63914, is cited as affected). Restrict internet-facing access to PaperCut servers and hunt for signs of post-exploitation, given confirmed use to deliver Cl0p and LockBit ransomware. US federal agencies must apply mitigations per CISA BOD 22-01 (or vendor instructions) or discontinue use of the product if mitigations are unavailable.

7.578% KEV ransomware
  • PaperCut NG 22.0.5 (Build 63914) explicitly cited as affected; CISA lists PaperCut NG broadly without a full version range
  • PaperCut MF affected per CISA listing; no specific version range provided in the data
large≈75,000+ sites/organizations (PaperCut NG/MF is deployed at tens of thousands of organizations; public scans have found thousands of servers directly…
CVE-2024-27199
Path Traversal in JetBrains TeamCity Allows Limited Admin Actions

JetBrains TeamCity, a widely used continuous integration/continuous delivery (CI/CD) server, contains a relative path traversal vulnerability (CWE-23) in which the application fails to properly neutralize traversal sequences in file paths. An attacker who can reach the vulnerable component can supply crafted relative paths that escape the intended directory, gaining the ability to perform limited administrative actions on the TeamCity server. Any organization running an affected JetBrains TeamCity deployment, especially instances exposed to the internet or reachable by untrusted users, is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20 with known ransomware use, and the EPSS model assigns it a 100% probability of exploitation within the next 30 days. No public proof-of-concept is known, but the KEV listing confirms active exploitation in the wild per CISA.

Do: Upgrade TeamCity to the patched release identified in JetBrains' security bulletin, or if patching is not immediately possible, apply vendor-recommended mitigations and restrict internet access to the server; federal agencies must follow BOD 22-01 guidance, including for cloud service offerings, or discontinue use if mitigations are unavailable. Given the known ransomware association, review TeamCity logs, admin accounts, and build-agent activity for signs of tampering as part of remediation.

7.3100% KEV ransomware PoC
  • JetBrains TeamCity Affected as listed by CISA; the source data provides no specific affected version ranges, so verify exact affected and patched versions in JetBrains' security b
large~10,000-30,000 TeamCity server deployments, with a meaningful share of those exposed directly to the internet (order of magnitude 10^4)
CVE-2025-2749
Path Traversal to Authenticated RCE in Kentico Xperience Through 13.0.178

CVE-2025-2749 is a path traversal and unrestricted file upload flaw (CWE-22/CWE-434) in the Staging Sync Server component of Kentico Xperience, exploitable by an authenticated user with staging sync privileges. The user can upload arbitrary data to path-relative locations, escaping the intended upload directory and writing attacker-controlled files — including executable server-side content such as script files — anywhere the application can reach, resulting in remote code execution on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 3.1: 7.2 High, network-accessible with high privileges required). All Kentico Xperience versions through 13.0.178 are affected, primarily deployments where the Staging Sync Server endpoint is reachable by attackers or by accounts with weak or stolen credentials. The flaw is confirmed actively exploited — it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-20 — and a public technical write-up with proof-of-concept details is available from watchTowr Labs.

Do: Upgrade Kentico Xperience to a hotfix release later than 13.0.178 per the vendor's instructions (federal agencies must follow BOD 22-01 guidance or the KEV-required action by the stated deadline). Until patched, restrict access to the Staging Sync Server endpoint (e.g., via VPN/firewall allowlisting) and review high-privilege staging/sync accounts for suspicious use. Hunt for signs of compromise such as unexpected executable or script files uploaded outside intended directories and webshells in the web root, since the vulnerability is listed in CISA's KEV as actively exploited.

7.24% KEV PoC
  • Kentico Xperience all versions through 13.0.178 (inclusive)
large≈ tens of thousands (10k–100k) of Kentico Xperience deployments, with an unknown but smaller subset exposing the staging sync endpoint to the internet
CVE-2025-32975
Authentication Bypass in Quest KACE Systems Management Appliance (SSO)

Quest KACE Systems Management Appliance (SMA) versions in the 13.0.x through 14.1.x branches, prior to the fixed builds, contain an improper authentication flaw (CWE-287) in the SSO authentication handling mechanism. Because the bypass requires no valid credentials, privileges, or user interaction and is reachable over the network, an attacker who can reach the appliance can impersonate legitimate users and achieve complete administrative takeover. Any organization running an affected SMA build is exposed, particularly where the appliance's web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, and press reporting describes attackers hijacking unpatched SMA systems, with compromises at roughly 60 organizations cited; ransomware use is not yet confirmed.

Do: Upgrade affected SMA deployments to the fixed build for their branch — 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4) or later — prioritizing internet-facing appliances. Since the flaw is actively exploited and grants full admin takeover, review appliance logs and administrator accounts for signs of compromise (unexpected SSO sessions, new or altered accounts) and restrict access to the SMA web interface to trusted networks per Quest's guidance. U.S. federal agencies must apply the required mitigations or discontinue use under BOD 22-01 by the KEV deadline.

10.02% KEV
  • Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385
  • Quest KACE Systems Management Appliance (SMA) 13.1.x before 13.1.81
  • Quest KACE Systems Management Appliance (SMA) 13.2.x before 13.2.183
  • +2 more
largetens of thousands of deployed SMA appliances worldwide, with likely only a low-thousands subset internet-exposed
CVE-2025-48700
Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, and 10.1 contain a cross-site scripting (XSS) flaw in the Classic UI caused by insufficient sanitization of HTML email content, involving crafted tag structures and attribute values that use @import directives and other script injection vectors. An attacker triggers it simply by getting a user to view a crafted email message in the Classic UI, with no additional user interaction required. Successful exploitation executes arbitrary JavaScript within the victim's session, potentially exposing sensitive mailbox information or enabling unauthorized actions under the victim's identity. Any organization running the affected ZCS branches — particularly internet-facing mail servers whose users receive untrusted email — is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, confirming active exploitation in the wild; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at about 1.7%.

Do: Upgrade ZCS to the latest patched builds of the affected 8.8.15/9.0/10.0/10.1 branches per Synacor/Zimbra's security advisory (no specific fixed version is listed here); federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Because the flaw is specific to the Classic UI, having users work in the Modern UI instead of the Classic UI reduces exposure until patching is complete. Review mail server and web client logs for users who viewed suspicious HTML-formatted messages as an indicator of targeting.

6.12% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) Classic UI 8.8.15, 9.0, 10.0, and 10.1
largeon the order of tens of thousands of internet-exposed Zimbra servers
CVE-2026-20122
Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown.

Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable.

5.425% KEV
  • Cisco Catalyst SD-WAN Manager
large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide
CVE-2026-20133
+1 in the same advisory: …20128
Actively Exploited Information Disclosure in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager, the central management and monitoring platform for Cisco SD-WAN fabrics (formerly known as vManage), contains a sensitive-information-exposure flaw (CWE-200) that allows remote attackers to view sensitive information on affected systems. The available data does not specify the exact trigger path or authentication requirements, but the flaw is remotely exploitable by unauthorized actors. An attacker gains access to sensitive information held on the management platform, which aggregates inventory, configuration, and telemetry for an entire SD-WAN overlay, potentially aiding follow-on attacks. Any organization running an affected release of Cisco Catalyst SD-WAN Manager is in scope. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-04-20, confirming exploitation in the wild, and EPSS assigns a 31.4% probability of exploitation within 30 days (98th percentile), although CVSS scoring is pending and no public proof-of-concept is known.

Do: Inventory your environment for internet-exposed Catalyst SD-WAN Manager instances and review access logs for signs of unauthorized retrieval of sensitive information, since the flaw is listed as exploited in the wild. Apply the vendor fix referenced in Cisco's advisory for CVE-2026-20133 when available, and follow CISA's Emergency Directive 26-03 and the CISA 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'; federal agencies must adhere to applicable BOD 22-01 mitigation timelines or discontinue use of the product if mitigations are unavailable.

7.531% KEV
  • Cisco Catalyst SD-WAN Manager
large≈tens of thousands of deployments (Cisco has publicly cited 30,000+ SD-WAN customers, each operating at least one Manager controller)
Full article577 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
  • CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability
  • CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability
  • CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability
  • CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
  • CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
  • CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
  • CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Several of the listed vulnerabilities are not just theoretical weaknesses but have been actively exploited in real-world attacks, often becoming entry points for ransomware operators and state-linked actors.

The CVE-2023-27351 flaw in PaperCut NG/MF is a clear example. It was widely abused in 2023 by ransomware groups such as the Clop ransomware group and LockBit, which leveraged the improper authentication issue to gain unauthenticated access to servers, deploy payloads, and move laterally within networks.

Similarly, CVE-2024-27199 affecting JetBrains TeamCity was rapidly weaponized after disclosure. Threat actors exploited the path traversal flaw to access sensitive configuration files, extract credentials, and in some cases deploy backdoors on build servers, critical assets in software supply chains.

The CVE-2025-32975 in Quest KACE Systems Management Appliance has also been observed in opportunistic attacks, where attackers bypass authentication to gain administrative access, enabling device management abuse and potential malware deployment across managed endpoints.

On the email front, CVE-2025-48700 impacting Zimbra Collaboration Suite has been linked to exploitation campaigns delivering malicious scripts via cross-site scripting, often used to hijack sessions or steal credentials in targeted attacks.

For the more recent Cisco issues, CVE-2026-20133, CVE-2026-20122, and CVE-2026-20128 affecting Cisco Catalyst SD-WAN Manager, public reporting so far indicates a high risk of exploitation, especially given the platform’s role in managing enterprise networks. While large-scale campaigns have not been as widely documented yet, similar Cisco management-plane flaws have historically been quickly adopted by threat actors once proof-of-concept exploits emerge.

Finally, CVE-2025-2749 in Kentico Xperience represents a classic path traversal issue. Although public evidence of widespread exploitation is still limited, such flaws are routinely abused in web attacks to access sensitive files, and they tend to be incorporated into automated scanning and exploitation frameworks shortly after disclosure.

Overall, the pattern is consistent: vulnerabilities enabling unauthenticated access, path traversal, or credential exposure are quickly operationalized. Attackers exploit them for initial access, privilege escalation, and persistence, often within days of public disclosure, highlighting the need for rapid patching and continuous monitoring.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by May 4, 2026, except Cisco Catalyst and Synacor Zimbra Collaboration Suite (ZCS) flaws, which must be addressed by April 23, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/191080/hacking/u-s-cisa-adds-cisco-catalyst-kentico-xperience-papercut-ng-mf-synacor-zcs-quest-kace-sma-and-jetbrains-teamcity-flaws-to-its-known-exploited-vulnerabilities-catalog.html