SharePoint Code-Injection Bug Joins CISA’s Must-Patch List After Real-World Attacks
CISA has added a Microsoft SharePoint code-injection flaw, CVE-2026-65660, to its Known Exploited Vulnerabilities catalog after confirming it is being used in live attacks. The agency gave federal...
CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...
CISA’s Latest Advice for Defenders: Lay Traps for Hackers Before They Even Get In
CISA has published new guidance urging organizations to seed their networks with fake credentials, decoy systems and honeytokens so that any attacker who slips past perimeter defenses trips...
CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits
CISA, the FBI, and HHS have jointly updated their advisory on the Medusa ransomware-as-a-service operation, which has now hit more than 500 critical infrastructure organizations spanning healthcare, education,...
CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9.6 in Severity
CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active...
Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns
CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...
CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw
CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federal agencies must remediate...
CISA Flags Actively Exploited Ubiquiti UniFi OS Vulnerabilities — Patch Deadline June 26
CISA has added three Ubiquiti UniFi OS vulnerabilities to its KEV catalog following confirmed active exploitation. Federal agencies must patch by June 26, 2026; the chained flaws enable...