CISA added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog on Monday due to evidence of active exploitation.
The list of flaws is as follows:
By infosecbulletin
/ Friday , September 18 2026
Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and one of three data-hosting zones in the...
Read More
By infosecbulletin
/ Friday , September 18 2026
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
By infosecbulletin
/ Thursday , September 17 2026
Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
By infosecbulletin
/ Thursday , September 17 2026
GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
By infosecbulletin
/ Monday , September 14 2026
Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
By infosecbulletin
/ Saturday , September 12 2026
German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
By infosecbulletin
/ Friday , September 11 2026
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
CVE-2014-3931 (CVSS score: 9.8) A buffer overflow vulnerability in Multi-Router Looking Glass (MRLG) that could allow remote attackers to cause an arbitrary memory write and memory corruption.
CVE-2016-10033 (CVSS score: 9.8) A command injection vulnerability in PHPMailer that could allow an attacker to execute arbitrary code within the context of the application or result in a denial-of-service (DoS) condition.
CVE-2019-5418 (CVSS score: 7.5) A path traversal vulnerability in Ruby on Rails’ Action View that could cause contents of arbitrary files on the target system’s file system to be exposed
CVE-2019-9621 (CVSS score: 7.5) A Server-Side Request Forgery (SSRF) vulnerability in the Zimbra Collaboration Suite that could result in unauthorized access to internal resources and remote code execution.
No public reports exist on the exploitation of the first three vulnerabilities in real attacks. However, Trend Micro linked the exploitation of CVE-2019-9621 to a Chinese threat actor named Earth Lusca in September 2023, who used it to deploy web shells and Cobalt Strike.
Billions Of Gmail And Outlook Users At Risk