Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > CISA KEV
#CISA KEV

CISA Orders Urgent ScreenConnect Response as Attackers Exploit Critical Flaw

17 September 2026  |  dark6  |  Vulnerability

CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect authorization flaw and ordered rapid remediation for covered agencies. Organizations should patch immediately and investigate prior remote sessions,...

>> read more

CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack

12 September 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...

>> read more

CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List

11 September 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...

>> read more

Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release

28 August 2026  |  dark6  |  Vulnerability

PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...

>> read more

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

28 August 2026  |  dark6  |  Vulnerability

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...

>> read more

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

27 August 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...

>> read more

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

20 August 2026  |  dark6  |  Vulnerability

CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...

>> read more