Tag: known exploited vulnerabilities (KEVs)

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack
News

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a major security issue affecting Adobe Experience Manager to its list of known exploited vulnerabilities (KEVs). This vulnerability is a maximum-severity misconfiguration problem called CVE-2025-54253 (CVSS score: 10.0), which has the potential to cause arbitrary code execution. The flaw affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and below, according to Adobe. Version 6.5.0-0108, which was made available in early August 2025, addressed it along with CVE-2025-54254 (CVSS score: 8.6). According to security firm FireCompass, the vulnerability arises from the potentially vulnerable /adminui/debug servlet, which interprets user-supplied ...
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
News

Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence

With evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently revealed major security hole affecting the open-source Langflow platform to its list of known exploited vulnerabilities (KEVs). Tracked as CVE-2025-3248, the vulnerability has a CVSS score of 9.8 out of 10.0. According to CISA, Langflow's /api/v1/validate/code endpoint has a missing authentication vulnerability that enables a remote, unauthenticated attacker to run arbitrary code through carefully constructed HTTP requests. In particular, it has been discovered that the endpoint incorrectly uses Python's built-in exec() function on user-supplied code without sufficient sandboxing or authentication, enabling attackers to run arbitrary commands on the server. ...
CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices
News

CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices

Based on indications of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security vulnerability affecting SonicWall Secure Mobile Access (SMA) 100 Series gateways to its list of known exploited vulnerabilities (KEVs). Tracked as CVE-2021-20035 (CVSS score: 7.2), the high-severity vulnerability pertains to an instance of operating system command injection that may lead to code execution. According to a September 2021 advisory from SonicWall, "a remote authenticated attacker can inject arbitrary commands as a 'nobody' user if special elements in the SMA100 management interface are not properly neutralized. This could potentially result in code execution." The defect affects devices running the versions of read more about CIS...
CISA Warns of Active Exploitation in GitHub Action Supply Chain Compromise
News

CISA Warns of Active Exploitation in GitHub Action Supply Chain Compromise

On Tuesday, the GitHub Action's supply chain compromise vulnerability, tj-actions/changed-files, was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEVs). The high-severity vulnerability, identified as CVE-2025-30066 (CVSS score: 8.6), is related to a GitHub Action breach that allows a remote attacker to insert malicious code and access private information through action logs. According to a CISA alert, the tj-actions/changed-files GitHub Action has an embedded malicious code vulnerability that enables a remote attacker to access action logs and uncover secrets. Valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys are a few examples of these secrets read more about CISA ...
CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability
News

CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a severe security hole that has been patched and affects Palo Alto Networks Expedition to its list of known exploited vulnerabilities (KEVs). The Expedition migration program has a vulnerability known as CVE-2024-5910 (CVSS score: 9.3) that involves a situation of missing authentication that could result in an admin account takeover. According to an alert from CISA, Palo Alto Expedition has a missing authentication vulnerability that enables a network-connected attacker to take control of an admin account and perhaps acquire credentials, configuration secrets, and other data read more about CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulner...