CISA KEV

Security Notices
CISA Adds Apache Struts Command Injection to KEVNew!!

Apache issued CISA KEV: CVE-2016-3081 for Apache Struts. Match affected deployments, apply supported fixes, validate operations, and retain evidence.

Read this guide
Security Notices
CISA Adds ISC BIND TKEY Denial of Service to KEVNew!!

ISC issued CISA KEV: CVE-2015-5477 for ISC BIND. Match affected deployments, apply supported fixes, validate operations, and retain evidence.

Read this guide
Security Notices
CISA Adds ONLYOFFICE Docs Path Traversal to KEVNew!!

ONLYOFFICE issued CISA KEV: CVE-2021-3199 for ONLYOFFICE Docs. Match affected deployments, apply supported fixes, validate operations, and retain evidence.

Read this guide
Security Notices
CISA Adds ProFTPD Arbitrary File Access to KEVNew!!

ProFTPD issued CISA KEV: CVE-2015-3306 for ProFTPD. Match affected deployments, apply supported fixes, validate operations, and retain evidence.

Read this guide
Security Notices
CISA Adds Strapi Sensitive-Data Exposure to KEVNew!!

Strapi issued CISA KEV: CVE-2023-22894 for Strapi. Match affected deployments, apply supported fixes, validate operations, and retain evidence.

Read this guide
Security Notices
CISA Adds Exploited Apple File-Processing Flaw to KEV

Apple's crafted-file code-execution flaw is listed in CISA KEV, with Apple reporting possible targeted exploitation. Prioritize supported devices and high-risk users, apply the matching update, and preserve evidence; patching does not establish absence of prior compromise.

Read this guide
Security Notices
CISA Adds WordPress Core Remote File Inclusion to KEV

CISA lists an exploited WordPress template-resolution flaw that can include local PHP files under specific theme and server conditions. Update the affected core branch, preserve suspicious files and logs, and conduct forensic triage.

Read this guide
Security Notices
CISA Adds MikroTik RouterOS SSH Bypass to KEV

The KEV-listed RouterOS SSH bypass requires branch-matched updates and management-access restrictions. Preserve recovery access and inspect router configuration and security indicators; a successful patch or clean indicator alone does not establish an uncompromised appliance.

Read this guide
Security Notices
CISA Adds Microsoft SharePoint Code Injection to KEV

CISA lists an exploited SharePoint code-injection flaw requiring a low-privilege authenticated attacker but no further user interaction. Update every affected farm server through Microsoft's supported workflow and preserve evidence for forensic triage.

Read this guide
Security Notices
CISA Adds Zyxel GS1900 Command Execution Flaw to KEV

The exploited Zyxel GS1900 flaw lets an unauthenticated LAN attacker execute commands through a vulnerable CGI program. Restrict management access, preserve logs for triage, and install firmware matched to the exact switch model.

Read this guide