U.S. CISA adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 17, 07:39 UTC · Apr 17, 2026Exploit / PoC in the wildCVE-2026-3419760
CISA cancels summer internships for cyber scholarship students amid DHS funding lapseCyberScoop·Apr 14, 23:17 UTC · Apr 14, 2026Exploit / PoC in the wild60
U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 14, 07:38 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2026-34621CVE-2012-1854CVE-2020-9715+4 CVEs260
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 21:35 UTC · Apr 8, 2026Exploit / PoC in the wildCVE-2026-134060
U.S. CISA adds a flaw in Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 7, 09:02 UTC · Apr 7, 2026Exploit / PoC in the wildCVE-2026-3561660
U.S. CISA adds a flaw in F5 BIG-IP AMP to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 5, 17:52 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2025-5352160
U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 4, 16:43 UTC · Apr 4, 2026Exploit / PoC in the wildCVE-2026-350260
U.S. CISA adds a flaw in Google Dawn to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 1, 23:30 UTC · Apr 1, 2026Exploit / PoC in the wildCVE-2026-528160
U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 31, 09:31 UTC · Mar 31, 2026Exploit / PoC in the wildCVE-2026-3055CVE-2023-4966CVE-2026-436860
U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 10:15 UTC · Mar 27, 2026Exploit / PoC in the wildCVE-2026-3363460
U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 26, 21:05 UTC · Mar 26, 2026Exploit / PoC in the wildCVE-2026-33017CVE-2025-324860
U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 22, 14:40 UTC · Mar 22, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-32432CVE-2025-43510+3 CVEs60
U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 19, 17:37 UTC · Mar 19, 2026Exploit / PoC in the wildCVE-2026-2013160
U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 18, 21:11 UTC · Mar 18, 2026Exploit / PoC in the wildCVE-2026-20963CVE-2025-6637660
U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 16, 21:08 UTC · Mar 16, 2026Exploit / PoC in the wildCVE-2025-4781360
U.S. CISA adds Google Chrome flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 13, 22:05 UTC · Mar 13, 2026Exploit / PoC in the wildCVE-2026-3909CVE-2026-391060
U.S. CISA adds a flaw in n8n to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 12, 08:46 UTC · Mar 12, 2026Exploit / PoC in the wildCVE-2025-6861360
FBI says even in an AI-powered world, security basics still matterCyberScoop·Mar 10, 19:31 UTC · Mar 10, 2026Exploit / PoC in the wild60
U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 10, 09:52 UTC · Mar 10, 2026Exploit / PoC in the wildCVE-2021-22054CVE-2025-26399CVE-2026-160360
U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 6, 08:42 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2023-43000CVE-2017-7921CVE-2021-22681+2 CVEs60
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV CatalogThe Hacker News·Mar 6, 06:30 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2017-7921CVE-2021-2268160
U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 4, 08:56 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2026-22719CVE-2026-2138560
ClawJacked flaw exposed OpenClaw users to data theftSecurity Affairs·Mar 2, 09:42 UTC · Mar 2, 2026Exploit / PoC60
U.S. CISA adds Cisco SD-WAN flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 26, 15:04 UTC · Feb 26, 2026Exploit / PoC in the wildCVE-2022-20775CVE-2026-2012760
U.S. CISA adds a flaw in Soliton Systems K.K FileZen to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 25, 09:23 UTC · Feb 25, 2026Exploit / PoC in the wildCVE-2026-2510860
U.S. CISA adds RoundCube Webmail flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 21, 11:19 UTC · Feb 21, 2026Exploit / PoC in the wildCVE-2025-49113CVE-2025-6846160
U.S. CISA adds Dell RecoverPoint and GitLab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 19, 15:16 UTC · Feb 19, 2026Exploit / PoC in the wildCVE-2021-22175CVE-2026-22769CVE-2020-779660
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password ManagersThe Hacker News·Feb 18, 05:49 UTC · Feb 18, 2026Exploit / PoC in the wild60
U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 14, 16:27 UTC · Feb 14, 2026Exploit / PoC in the wildCVE-2026-1731CVE-2026-2485860
U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 13, 08:27 UTC · Feb 13, 2026Exploit / PoC in the wildCVE-2024-43468CVE-2025-15556CVE-2025-40536+1 CVEs60
Acting CISA chief says DHS funding lapse would limit, halt some agency workCyberScoop·Feb 11, 22:04 UTC · Feb 11, 2026Exploit / PoC in the wild60
U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 11, 07:37 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+3 CVEs160
After major Poland energy grid cyberattack, CISA issues warning to U.S. audienceCyberScoop·Feb 10, 16:05 UTC · Feb 10, 2026Exploit / PoC in the wild60
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
U.S. CISA adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 3, 21:06 UTC · Feb 3, 2026Exploit / PoC in the wildCVE-2019-19006CVE-2021-39935CVE-2025-40551+1 CVEs60
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 30, 10:40 UTC · Jan 30, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-2485860
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 28, 19:26 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-2485860
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 27, 14:54 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2018-14634CVE-2025-52691CVE-2026-21509+2 CVEs60
Industry, government, nonprofits weigh voluntary rules for commercial hacking toolsCyberScoop·Jan 26, 14:11 UTC · Jan 26, 2026Exploit / PoC in the wild60
U.S. CISA adds a flaw in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 24, 10:23 UTC · Jan 24, 2026Exploit / PoC in the wildCVE-2024-37079CVE-2024-37080CVE-2024-38813+1 CVEs160