Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > CISA KEV
#CISA KEV

CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List

11 September 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...

>> read more

Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release

28 August 2026  |  dark6  |  Vulnerability

PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...

>> read more

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

28 August 2026  |  dark6  |  Vulnerability

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...

>> read more

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

27 August 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...

>> read more

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

20 August 2026  |  dark6  |  Vulnerability

CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...

>> read more

SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access

17 July 2026  |  dark6  |  Vulnerability

Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor's advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active...

>> read more

CISA Sounds Alarm as Attackers Exploit Critical FortiSandbox Command Injection Flaws

17 July 2026  |  dark6  |  Vulnerability

CISA has confirmed active exploitation of two OS command injection vulnerabilities in Fortinet's FortiSandbox product line, adding both to its Known Exploited Vulnerabilities catalog and giving federal agencies...

>> read more