U.S. CISA adds a flaw in Google Dawn to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 1, 23:30 UTC · Apr 1, 2026Exploit / PoC in the wildCVE-2026-528160
U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 26, 21:05 UTC · Mar 26, 2026Exploit / PoC in the wildCVE-2026-33017CVE-2025-324860
U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 6, 08:42 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2023-43000CVE-2017-7921CVE-2021-22681+2 CVEs60
U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 14, 16:27 UTC · Feb 14, 2026Exploit / PoC in the wildCVE-2026-1731CVE-2026-2485860
U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 11, 07:37 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+3 CVEs160
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 30, 10:40 UTC · Jan 30, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-2485860
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 28, 19:26 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-2485860
U.S. CISA adds a flaw in WatchGuard Fireware OS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 20, 10:26 UTC · Dec 20, 2025Exploit / PoC in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
U.S. CISA adds Cisco, SonicWall, and ASUS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 18, 10:18 UTC · Dec 18, 2025Exploit / PoC in the wildCVE-2025-20393CVE-2025-40602CVE-2025-59374+1 CVEs60
U.S. CISA adds new OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 4, 21:56 UTC · Dec 4, 2025Exploit / PoC in the wildCVE-2021-26828CVE-2021-2682960
U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 13:48 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
U.S. CISA adds WatchGuard Firebox, Microsoft Windows, and Gladinet Triofox flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 13, 11:29 UTC · Nov 13, 2025Exploit / PoC in the wildCVE-2025-9242CVE-2025-12480CVE-2025-62215+2 CVEs60
U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 29, 08:39 UTC · Oct 29, 2025Exploit / PoC in the wildCVE-2025-6204CVE-2025-6205CVE-2025-508660
U.S. CISA adds Oracle, Windows, Kentico, Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 21, 14:10 UTC · Oct 21, 2025Exploit / PoC in the wildCVE-2022-48503CVE-2025-2746CVE-2025-2747+3 CVEs60
U.S. CISA adds Google Chromium flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 21:39 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-1058560
U.S. CISA adds Oracle, Mozilla, Microsoft Windows, Linux Kernel, and Microsoft IE flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 07:00 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2010-3765CVE-2010-3962CVE-2011-3402+4 CVEs60
U.S. CISA adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 4, 15:49 UTC · Oct 4, 2025Exploit / PoC in the wildCVE-2014-6278CVE-2015-7755CVE-2017-1000353+5 CVEs60
U.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 30, 09:07 UTC · Sep 30, 2025Exploit / PoC in the wildCVE-2021-21311CVE-2025-20352CVE-2025-10035+3 CVEs60
Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation DirectiveThe Hacker News·Sep 26, 05:35 UTC · Sep 26, 2025Exploit / PoC in the wildCVE-2025-20333CVE-2025-2036260
U.S. CISA adds Sitecore, Android, and Linux flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 18:23 UTC · Sep 25, 2025Exploit / PoC in the wildCVE-2025-38352CVE-2025-48543CVE-2025-5369060
U.S. CISA adds Dassault Systèmes DELMIA Apriso flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 12, 05:58 UTC · Sep 12, 2025Exploit / PoC in the wildCVE-2025-5086CVE-2025-53690CVE-2025-38352+1 CVEs60
CISA taps Nicholas Andersen for executive assistant director of cybersecurityCyberScoop·Sep 2, 20:03 UTC · Sep 2, 2025Exploit / PoC in the wild60
U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 14, 08:03 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-8875CVE-2025-887660
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 30, 18:51 UTC · Jun 30, 2025Exploit / PoC in the wildCVE-2025-6543CVE-2023-6548CVE-2023-654960
U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 22, 22:17 UTC · May 22, 2025Exploit / PoC in the wildCVE-2025-463260
U.S. CISA adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 1, 20:46 UTC · May 1, 2025Exploit / PoC in the wildCVE-2025-1976CVE-2025-42599CVE-2025-392860
Is Ivanti the problem or a symptom of a systemic issue with network devices?CyberScoop·Apr 14, 13:57 UTC · Apr 14, 2025Exploit / PoC in the wild60
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 10, 18:26 UTC · Apr 10, 2025Exploit / PoC in the wildCVE-2024-53197CVE-2024-53150CVE-2025-30406+1 CVEs60
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
U.S. CISA adds six Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 12, 19:18 UTC · Mar 12, 2025Exploit / PoC in the wildCVE-2025-24983CVE-2025-24984CVE-2025-24985+3 CVEs60
U.S. CISA adds Advantive VeraCore and Ivanti EPM flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 11, 08:03 UTC · Mar 11, 2025Exploit / PoC in the wildCVE-2025-25181CVE-2024-57968CVE-2024-13159+2 CVEs60
Karen Evans steps into a leading federal cyber position: executive assistant director for cybersecurity at CISACyberScoop·Feb 26, 19:01 UTC · Feb 26, 2025Exploit / PoC in the wild60
U.S. CISA adds Craft CMS and Palo Alto Networks PAN-OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 21, 10:40 UTC · Feb 21, 2025Exploit / PoC in the wildCVE-2025-23209CVE-2025-0111CVE-2025-0108+1 CVEs60
U.S. CISA adds Apple iOS and iPadOS and Mitel SIP Phones flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 15, 17:37 UTC · Feb 15, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2024-4171060
U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 7, 21:54 UTC · Feb 7, 2025Exploit / PoC in the wildCVE-2025-099460
U.S. CISA adds Fortinet FortiOS flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 17, 14:29 UTC · Jan 17, 2025Exploit / PoC in the wildCVE-2024-55591CVE-2025-21333CVE-2025-21334+1 CVEs60
U.S. CISA adds Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 23, 13:50 UTC · Oct 23, 2024Exploit / PoC in the wildCVE-2024-3809460
U.S. CISA adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 11:10 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-43047CVE-2024-43572CVE-2024-4357360
U.S. CISA adds new Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 07:42 UTC · Sep 25, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-896360
CISA adds NextGen Healthcare Mirth Connect flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 21, 19:59 UTC · May 21, 2024Exploit / PoC in the wildCVE-2023-43208CVE-2024-494760