Kev Catalog
The latest Kev Catalog coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA KEV Update 2025: Critical Patches for Cisco, SonicWall, ASUS Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical update to its Known Exploited Vulnerabilities (KEV) catalog, adding three high-severity vulnerabilities affecting...
Fortinet SAML Flaw CVE-2025-59718: Critical Admin Bypass Threat Demands Immediate Patching
The cybersecurity landscape has been jolted by the discovery of CVE-2025-59718, a critical authentication bypass vulnerability in Fortinet's FortiGate firewalls and FortiProxy web proxies that allows...
CVE-2025-14174: Critical Chrome ANGLE GPU Vulnerability Added to KEV Catalog
Google's Chromium project has patched a high-risk graphics vulnerability, tracked as CVE-2025-14174, that allowed out-of-bounds memory access in the ANGLE graphics translation layer. This security...
CISA Adds Gladinet Crypto Flaw & Apple WebKit Bug to KEV Catalog: Critical Security Alert
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated its warnings about two critical vulnerabilities that are actively being exploited in the wild, adding them to its Known...
CISA Flags Sierra Wireless AirLink CVE-2018-4063: Critical IoT Gateway Patch Now Mandatory
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated a six-year-old vulnerability in Sierra Wireless AirLink gateways to critical status, adding CVE-2018-4063 to its Known...
CISA Adds D-Link Router & New Critical Flaw to KEV Catalog: What Windows Users Must Know
The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog with two significant additions this week, highlighting ongoing threats to...
CISA Adds ScadaBR HMI XSS Vulnerability to KEV Catalog: Urgent Patch Required
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2021-26829, a critical stored Cross-Site Scripting (XSS) vulnerability in OpenPLC's ScadaBR Human-Machine...
CVE-2025-13223: Chrome V8 Type Confusion Bug Added to CISA KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated a critical Chromium V8 engine vulnerability to its highest priority level by adding CVE-2025-13223 to the Known Exploited...
CVE-2025-64446 FortiWeb Path Traversal: Critical Vulnerability Now in KEV Catalog
Fortinet has issued an urgent security advisory for a critical path traversal vulnerability in FortiWeb web application firewalls that has already been added to CISA's Known Exploited Vulnerabilities...
FortiWeb CVE-2025-25257 SQL Injection Vulnerability: Urgent Patch Required
The cybersecurity landscape faces another critical threat as CISA adds Fortinet's FortiWeb vulnerability CVE-2025-25257 to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active...
Active Exploitation Confirmed: CISA Adds Three Critical CVEs for Firebox, Triofox, Windows Kernel
The Cybersecurity and Infrastructure Security Agency (CISA) has escalated its security warnings by adding three new critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog,...
CISA warns Samsung image codec bug under active attack; patch February 2025 update now
The Cybersecurity and Infrastructure Security Agency (CISA) has urgently added a critical Samsung mobile vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active...