CISA KEV
CISA Adds Apache Struts Command Injection to KEVNew!!
Apache issued CISA KEV: CVE-2016-3081 for Apache Struts. Match affected deployments, apply supported fixes, validate operations, and retain evidence.
CISA Adds ISC BIND TKEY Denial of Service to KEVNew!!
ISC issued CISA KEV: CVE-2015-5477 for ISC BIND. Match affected deployments, apply supported fixes, validate operations, and retain evidence.
CISA Adds ONLYOFFICE Docs Path Traversal to KEVNew!!
ONLYOFFICE issued CISA KEV: CVE-2021-3199 for ONLYOFFICE Docs. Match affected deployments, apply supported fixes, validate operations, and retain evidence.
CISA Adds ProFTPD Arbitrary File Access to KEVNew!!
ProFTPD issued CISA KEV: CVE-2015-3306 for ProFTPD. Match affected deployments, apply supported fixes, validate operations, and retain evidence.
CISA Adds Strapi Sensitive-Data Exposure to KEVNew!!
Strapi issued CISA KEV: CVE-2023-22894 for Strapi. Match affected deployments, apply supported fixes, validate operations, and retain evidence.
CISA Adds WordPress Core Remote File Inclusion to KEV
CISA lists an exploited WordPress template-resolution flaw that can include local PHP files under specific theme and server conditions. Update the affected core branch, preserve suspicious files and logs, and conduct forensic triage.
CISA Adds MikroTik RouterOS SSH Bypass to KEV
The KEV-listed RouterOS SSH bypass requires branch-matched updates and management-access restrictions. Preserve recovery access and inspect router configuration and security indicators; a successful patch or clean indicator alone does not establish an uncompromised appliance.
CISA Adds Microsoft SharePoint Code Injection to KEV
CISA lists an exploited SharePoint code-injection flaw requiring a low-privilege authenticated attacker but no further user interaction. Update every affected farm server through Microsoft's supported workflow and preserve evidence for forensic triage.
CISA Adds Zyxel GS1900 Command Execution Flaw to KEV
The exploited Zyxel GS1900 flaw lets an unauthenticated LAN attacker execute commands through a vulnerable CGI program. Restrict management access, preserve logs for triage, and install firmware matched to the exact switch model.
