U.S. CISA adds a flaw in Cisco Unified Communications products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 24, 09:52 UTC · Jan 24, 2026Exploit / PoC in the wildCVE-2026-2004560
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
U.S. CISA adds Prettier eslint-config-prettier, Vite Vitejs, Versa Concerto SD-WAN orchestration platform and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 23, 11:50 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-31125CVE-2025-34026CVE-2025-54313+1 CVEs60
CISA Flags Microsoft Office and HPE OneView Bugs as Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wildCVE-2009-0556CVE-2025-37164160
U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 14, 11:45 UTC · Jan 14, 2026Exploit / PoC in the wildCVE-2026-2080560
U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 12, 21:55 UTC · Jan 12, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
CISA Closes Ten Emergency Directives After Federal Cyber ReviewsInfosecurity Magazine·Jan 12, 16:45 UTC · Jan 12, 2026Exploit / PoC in the wild60
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024The Hacker News·Jan 10, 08:49 UTC · Jan 10, 2026Exploit / PoC in the wild60
UAT-7290 targets high value telecommunications infrastructure in South AsiaCisco Talos·Jan 8, 11:00 UTC · Jan 8, 2026Exploit / PoC60
U.S. CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 8, 10:43 UTC · Jan 8, 2026Exploit / PoC in the wildCVE-2009-0556CVE-2025-37164160
U.S. CISA adds a Meta React Server Components flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 31, 19:34 UTC · Dec 31, 2025Exploit / PoC in the wildCVE-2025-5518260
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 30, 08:33 UTC · Dec 30, 2025Exploit / PoC in the wildCVE-2025-1484760
U.S. CISA adds a flaw in Digiever DS-2105 Pro to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 23, 08:43 UTC · Dec 23, 2025Exploit / PoC in the wildCVE-2023-5216360
U.S. CISA adds a flaw in WatchGuard Fireware OS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 20, 10:26 UTC · Dec 20, 2025Exploit / PoC in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
U.S. CISA adds Cisco, SonicWall, and ASUS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 18, 10:18 UTC · Dec 18, 2025Exploit / PoC in the wildCVE-2025-20393CVE-2025-40602CVE-2025-59374+1 CVEs60
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 17, 08:17 UTC · Dec 17, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-5971960
U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 15, 19:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-43529CVE-2025-14611CVE-2025-1417460
U.S. CISA adds Google Chromium and Sierra Wireless AirLink ALEOS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 15, 18:56 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-14174CVE-2018-4063160
U.S. CISA adds an OSGeo GeoServer flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 12, 09:24 UTC · Dec 12, 2025Exploit / PoC in the wildCVE-2025-58360CVE-2024-3640160
U.S. CISA adds Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 10, 09:42 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-6218CVE-2025-62221160
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
U.S. CISA adds new OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 4, 21:56 UTC · Dec 4, 2025Exploit / PoC in the wildCVE-2021-26828CVE-2021-2682960
U.S. CISA adds Android Framework flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 2, 21:12 UTC · Dec 2, 2025Exploit / PoC in the wildCVE-2025-48572CVE-2025-4863360
U.S. CISA adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 1, 08:59 UTC · Dec 1, 2025Exploit / PoC in the wildCVE-2021-2682960
U.S. CISA adds an Oracle Fusion Middleware flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:34 UTC · Nov 22, 2025Exploit / PoC in the wildCVE-2025-6175760
U.S. CISA adds a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 21:12 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-1322360
U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 13:48 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 15, 06:58 UTC · Nov 15, 2025Exploit / PoC in the wildCVE-2025-6444660
U.S. CISA adds WatchGuard Firebox, Microsoft Windows, and Gladinet Triofox flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 13, 11:29 UTC · Nov 13, 2025Exploit / PoC in the wildCVE-2025-9242CVE-2025-12480CVE-2025-62215+2 CVEs60
U.S. CISA adds Samsung mobile devices flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 11, 09:00 UTC · Nov 11, 2025Exploit / PoC in the wildCVE-2025-21042CVE-2025-2104360
U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 5, 08:06 UTC · Nov 5, 2025Exploit / PoC in the wildCVE-2025-11371CVE-2025-4870360
U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 30, 23:15 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-24893CVE-2025-4124460
U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 29, 08:39 UTC · Oct 29, 2025Exploit / PoC in the wildCVE-2025-6204CVE-2025-6205CVE-2025-508660
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360
U.S. CISA adds Microsoft WSUS, and Adobe Commerce and Magento Open Source flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 24, 19:05 UTC · Oct 24, 2025Exploit / PoC in the wildCVE-2025-54236CVE-2025-5928760
U.S. CISA adds Motex LANSCOPE flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 23, 10:49 UTC · Oct 23, 2025Exploit / PoC in the wildCVE-2025-6193260
U.S. CISA adds Oracle, Windows, Kentico, Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 21, 14:10 UTC · Oct 21, 2025Exploit / PoC in the wildCVE-2022-48503CVE-2025-2746CVE-2025-2747+3 CVEs60
U.S. CISA adds Adobe Experience Manager Forms flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 16, 16:40 UTC · Oct 16, 2025Exploit / PoC in the wildCVE-2025-5425360
U.S. CISA adds SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows, and IGEL OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 16, 08:56 UTC · Oct 16, 2025Exploit / PoC in the wildCVE-2016-7836CVE-2025-6264CVE-2025-24990+2 CVEs60
U.S. CISA adds Grafana flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 08:27 UTC · Oct 10, 2025Exploit / PoC in the wildCVE-2021-4379860