Cisa Kev Catalog
The latest Cisa Kev Catalog coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-48172 Under Active Attack: CISA Orders cPanel/LiteSpeed Patch by June 16
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical LiteSpeed cPanel plugin privilege-escalation flaw, tracked as CVE-2026-48172, to its Known Exploited Vulnerabilities...
CISA's Latest KEV Update: ScreenConnect Path Traversal and Windows Shell Spoofing Exploited in Wild
The Cybersecurity and Infrastructure Security Agency added two fresh vulnerabilities to its Known Exploited Vulnerabilities catalog on Monday, confirming that attackers are actively exploiting both a...
CISA Warns: Patch Samsung, SimpleHelp, D-Link Bugs Now Under Active Attack
CISA’s decision on April 24, 2026, to add four more flaws to its Known Exploited Vulnerabilities Catalog is another reminder that the most dangerous bugs are not always the ones with the highest...
CISA Adds Eight Actively Exploited Vulnerabilities to KEV Catalog: Critical Enterprise Tools at Risk
The Cybersecurity and Infrastructure Security Agency added eight new vulnerabilities to its Known Exploited Vulnerabilities Catalog on April 20, 2026. This update targets enterprise software and...
CISA Adds Critical Chrome Vulnerability CVE-2026-5281 to KEV Catalog: Immediate Action Required
The Cybersecurity and Infrastructure Security Agency has added CVE-2026-5281, a critical use-after-free vulnerability in Google Chrome's Dawn WebGPU implementation, to its Known Exploited...
CISA Adds Critical Citrix NetScaler Vulnerability to KEV Catalog—Patch Immediately
The Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities Catalog, signaling active exploitation in the wild....
CISA Adds Langflow Code Injection Vulnerability to KEV Catalog—Patch Immediately
The Cybersecurity and Infrastructure Security Agency has added a critical Langflow code injection vulnerability to its Known Exploited Vulnerabilities catalog, signaling active exploitation in the...
CVE-2026-20963 SharePoint Flaw Active in Attacks; CISA Orders Federal Patching by April 8
The Cybersecurity and Infrastructure Security Agency added CVE-2026-20963 to its Known Exploited Vulnerabilities Catalog on March 18, 2026. This Microsoft SharePoint deserialization-of-untrusted-data...
CISA Adds Zimbra XSS Vulnerability CVE-2025-66376 to KEV Catalog—Active Exploitation Confirmed
The Cybersecurity and Infrastructure Security Agency has added a critical cross-site scripting vulnerability in Zimbra Collaboration Suite to its Known Exploited Vulnerabilities catalog....
CISA KEV Catalog Adds Critical Magento & WSUS Vulnerabilities: What You Need to Know
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated its security warnings by adding two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, signaling...
CISA Adds Critical V8 JavaScript Engine Flaw to KEV Catalog: What You Need to Know
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated warnings about CVE-2025-6554, a newly discovered type confusion vulnerability in Chrome's V8 JavaScript engine, by adding it...
Citrix NetScaler CVE-2025-6543: Critical Patch to Prevent Remote Code Execution Attacks
Citrix NetScaler ADC and Gateway products, widely used in enterprise environments for secure remote access and application delivery, are under active exploitation due to a newly discovered critical...