Aggregator
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2018-14634 Linux Kernel Integer Overflow Vulnerability
- CVE-2025-52691 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
- CVE-2026-21509 Microsoft Office Security Feature Bypass Vulnerability
- CVE-2026-23760 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVE-2026-24061 GNU InetUtils Argument Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CVE-2026-23864: React and Next.js Denial of Service via Memory Exhaustion
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More
CISA says critical VMware RCE flaw now actively exploited
Massive Leak: 420,000 Israeli Business Records Exposed
You must login to view this content
学术前沿 | 西安交通大学蔺琛皓教授团队:跨场景下基于人机交互行为的儿童识别技术
Цукерберга вызывают на ковер. Оказывается, бесконечная лента в инстаграме – это не случайность, а ловушка
CVE-2023-39850 | Schoolmate 1.3 DeleteFunctions.php courseid/teacherid sql injection (EUVD-2023-43550)
CVE-2023-39841 | Etekcity 3-in-1 Smart Door Lock 1.0 RFID Tag missing encryption (EUVD-2023-43541)
CVE-2023-39842 | Digoo DG-HAMB Smart Home Security System 1.0 RFID Tag missing encryption (EUVD-2023-43542)
CVE-2023-39843 | Suleve 5-in-1 Smart Door Lock 1.0 RFID Tag missing encryption (EUVD-2023-43543)
CVE-2023-39846 | Konga 0.14.9 JWT Token improper authentication (EUVD-2023-43546)
CVE-2023-39834 | PbootCMS up to 3.1.x create_function command injection (EUVD-2023-43534)
CVE-2023-39828 | Tenda A18 15.13.07.09 formWifiBasicSet Security stack-based overflow (EUVD-2023-43528)
CVE-2023-39827 | Tenda A18 15.13.07.09 formAddMacfilterRule rule_info stack-based overflow (EUVD-2023-43527)
CVE-2023-39829 | Tenda A18 15.13.07.09 fromSetWirelessRepeat wpapsk_crypto2_4g stack-based overflow (EUVD-2023-43529)
CVE-2023-39809 | N.V.K.INTER iBSG 3.5 network-basic.php system_hostname command injection (EUVD-2023-43509)
CVE-2023-39810 | busybox 1.30.1/1.33.2 CPIO Archive path traversal (EUVD-2023-43510 / Nessus ID 235434)
Lazarus Hackers Actively Attacking European Drone Manufacturing Companies
Lazarus, a sophisticated North Korean-aligned hacking group also known as HIDDEN COBRA, has launched a new wave of targeted attacks against European drone manufacturers and defense contractors. The campaign, tracked as Operation DreamJob, emerged in late March 2025 and specifically targets organizations developing unmanned aerial vehicle technology across Central and Southeastern Europe. Researchers have identified […]
The post Lazarus Hackers Actively Attacking European Drone Manufacturing Companies appeared first on Cyber Security News.