By using this site, you agree to our Privacy Policy and Terms of Use.
Accept
VellaTimesVellaTimesVellaTimes
  • News
    NewsShow More
    A highly detailed rendering of the SMILE satellite orbiting Earth, with its solar panels deployed and the northern lights glowing in the background.
    SMILE Mission Launch: Satellite Prepares for Space
    March 22, 2026
    A sleek modern laptop displaying the Windows 11 desktop in a softly lit contemporary office setting, representing Microsoft's latest performance updates.
    Microsoft Reduces Windows 11 Copilot AI for Performance
    March 22, 2026
    A modern laptop displaying the Windows desktop on a brightly lit office desk.
    Windows 11 Update: Microsoft Cuts AI Bloat to Boost Speed
    March 22, 2026
    Weathered medical supply crates and a white relief tent in a dusty refugee camp, illustrating the delayed humanitarian aid and ongoing crisis in Sudan.
    Sudan Crisis Worsens as Middle East Conflict Disrupts Aid Supplies
    March 22, 2026
    A glowing laser beam illuminating a small stainless-steel disc in a high-tech physics laboratory setting.
    Nuclear Clock Breakthrough: A New Era of Timekeeping
    March 22, 2026
  • Technology
    TechnologyShow More
    A modern laptop displaying the Windows desktop on a brightly lit office desk.
    Windows 11 Update: Microsoft Cuts AI Bloat to Boost Speed
    March 22, 2026
    A majestic federal courthouse building in San Francisco with reporters and professionals gathered on the front steps.
    Elon Musk Found Liable in Twitter Investor Lawsuit
    March 22, 2026
    Professionals working and meeting in a modern technology office with computer screens showing generic AI software interfaces.
    OpenAI workforce plan aims for 8,000 staff by 2026
    March 22, 2026
    Digital stock market graphs and social media icons overlaid on a blurred, dramatic courtroom background.
    Elon Musk Twitter Lawsuit: Jury Finds Billionaire Liable
    March 21, 2026
    A modern smartphone displaying a glowing AI waveform on its screen, resting on a desk in a dimly lit tech office.
    Amazon Alexa Smartphone in Development Under Project Transformer
    March 21, 2026
  • AI
    AIShow More
    A sleek modern laptop displaying the Windows 11 desktop in a softly lit contemporary office setting, representing Microsoft's latest performance updates.
    Microsoft Reduces Windows 11 Copilot AI for Performance
    March 22, 2026
    Nvidia CEO Jensen Huang speaking on a conference stage with AI chip graphics on a large screen and an audience in the foreground.
    Nvidia GTC 2026 Spotlights Inference and AI Agents
    March 22, 2026
    A vibrant and modern open-plan technology office with professionals collaborating around futuristic screens.
    OpenAI Workforce Expansion: Staff to Double by 2026
    March 22, 2026
    Rows of illuminated high-tech server racks in a modern artificial intelligence data center facility.
    Nvidia CEO Jensen Huang Predicts $1 Trillion in AI Chip Sales at Nvidia GTC 2026
    March 21, 2026
    A computer monitor displaying search engine results with glowing digital code overlapping the news headlines, representing AI technology.
    Google AI Headline Rewrites Test Disrupts Search Results
    March 21, 2026
  • Science
    ScienceShow More
    A highly detailed rendering of the SMILE satellite orbiting Earth, with its solar panels deployed and the northern lights glowing in the background.
    SMILE Mission Launch: Satellite Prepares for Space
    March 22, 2026
    A glowing laser beam illuminating a small stainless-steel disc in a high-tech physics laboratory setting.
    Nuclear Clock Breakthrough: A New Era of Timekeeping
    March 22, 2026
    A cross-section view of the Martian landscape revealing an ancient river delta system buried deep beneath the red, rocky surface of Jezero Crater.
    NASA Rover Finds Ancient Buried River Delta on Mars
    March 22, 2026
    A medical professional wearing blue gloves holds a glowing blood sample vial in a modern clinical laboratory setting.
    New Blood Test Uses piRNAs to Predict Older Adult Survival
    March 21, 2026
    A hyper-realistic view of the NASA Perseverance rover exploring the rocky, red landscape of Jezero Crater on Mars under a clear sky.
    Ancient River Delta on Mars Discovered by NASA Rover
    March 21, 2026
  • World
    WorldShow More
    Weathered medical supply crates and a white relief tent in a dusty refugee camp, illustrating the delayed humanitarian aid and ongoing crisis in Sudan.
    Sudan Crisis Worsens as Middle East Conflict Disrupts Aid Supplies
    March 22, 2026
    US President and Japanese Prime Minister seated in the Oval Office during a tense diplomatic meeting with formal lighting and decor.
    Trump Pearl Harbor Remark Stuns Japanese Prime Minister
    March 22, 2026
    Split composition showing US and Ukrainian diplomatic flags in a boardroom alongside a subtle drone silhouette over a dark landscape.
    Ukraine and US Resume Peace Talks in Florida Amid Major Drone Strikes and Russian Advances
    March 22, 2026
    Colombian President Gustavo Petro stands at a podium in a formal setting during a press conference.
    Gustavo Petro Investigation: US Probes Alleged Drug Ties
    March 21, 2026
    Thick gray smoke billowing from an auto parts factory in Daejeon, South Korea, with multiple fire trucks and emergency personnel responding to the massive blaze.
    Massive Daejeon Auto Parts Factory Fire: Casualties and Rescue Efforts
    March 21, 2026
  • Bookmarks
Search
Category
  • News
  • Technology
  • AI
  • Science
  • World
Company
  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy
Resources
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
Reading: CISA KEV catalog expands with exploited flaws in 2026
Share
Notification Show More
Font ResizerAa
VellaTimesVellaTimes
Font ResizerAa
  • News
  • Technology
  • AI
  • Science
  • World
Search
  • Explore
    • News
    • Technology
    • AI
    • Science
    • World
  • Useful Links
    • About Us
    • Contact Us
    • Fact Checking Policy
    • Terms & Conditions
    • Privacy Policy
    • Copyright Policy
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
News

CISA KEV catalog expands with exploited flaws in 2026

Rakesh Paul
Last updated: 26/01/2026
Rakesh Paul
Share
10 Min Read
A cybersecurity analyst in a security operations center reviews a known exploited vulnerabilities alert on a computer monitor.

The CISA Known Exploited Vulnerabilities (KEV) catalog grew again in a series of January actions that flagged multiple security bugs as actively exploited, including issues tied to Zimbra Collaboration Suite, Versa Concerto, Vite, and the npm package eslint-config-prettier. Separate additions also warned of active exploitation involving Microsoft Office PowerPoint, HPE OneView, Gogs, and Cisco Unified Communications products, with federal remediation deadlines set under Binding Operational Directive 22-01.

Contents
Four newly added KEV entriesMicrosoft Office and HPE OneView addedGogs flaw flagged amid active exploitationCisco Unified CM zero-day added

CISA’s KEV catalog is used to highlight vulnerabilities with evidence of exploitation, and several of the newest entries point to remote code execution risks that can lead to major compromise if systems remain unpatched. The updates also show how both enterprise software and widely used open-source components can become targets, from collaboration platforms and SD-WAN tools to developer packages and self-hosted Git services.

Four newly added KEV entries

CISA added four vulnerabilities to the KEV catalog on Thursday, citing evidence of active exploitation in the wild. The four entries include CVE-2025-68645 in Synacor Zimbra Collaboration Suite (ZCS), CVE-2025-34026 in the Versa Concerto SD-WAN orchestration platform, CVE-2025-31125 in Vite (Vitejs), and CVE-2025-54313 related to embedded malicious code in eslint-config-prettier.

In Zimbra ZCS, CVE-2025-68645 is described as a PHP remote file inclusion issue that could let an attacker craft requests to the “/h/rest” endpoint to include arbitrary files from the WebRoot directory without authentication, and it was reported as fixed in November 2025 with version 10.1.13. For Versa Concerto, CVE-2025-34026 is described as an authentication bypass that could allow access to administrative endpoints, and it was reported as fixed in April 2025 with version 12.2.1 GA. For Vite, CVE-2025-31125 is described as an improper access control problem that could allow the contents of arbitrary files to be returned to the browser using “?inline&import” or “?raw?import,” with fixes listed across multiple versions released in March 2025.

The fourth entry, CVE-2025-54313, is tied to embedded malicious code in eslint-config-prettier that could enable execution of a malicious DLL called “Scavenger Loader,” which is designed to deliver an information stealer. The same report notes that CVE-2025-54313 refers to a supply chain attack that also targeted six other npm packages: eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall, got-fetch, and is. It adds that the campaign targeted package maintainers with bogus links that harvested credentials under the pretext of email verification, enabling threat actors to publish trojanized versions.

For the Zimbra issue, CrowdSec said exploitation targeting CVE-2025-68645 had been ongoing since January 14, 2026. The same account said there were no details on how the other three vulnerabilities were being exploited in the wild. Under BOD 22-01, Federal Civilian Executive Branch (FCEB) agencies were required to apply the needed fixes by February 12, 2026.

Microsoft Office and HPE OneView added

CISA also added two security flaws affecting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to the KEV catalog, citing evidence of active exploitation. The two vulnerabilities were listed as CVE-2009-0556, described as a code injection issue in Microsoft Office PowerPoint that can enable arbitrary code execution through memory corruption, and CVE-2025-37164, described as a code injection vulnerability in HPE OneView that can allow a remote unauthenticated user to perform remote code execution.

For CVE-2025-37164, details emerged when HPE said the flaw impacts all versions prior to version 11.00, and the company made available hotfixes for OneView versions 5.20 through 10. The same report said the scope and source of attacks targeting the two flaws were unclear and that there appeared to be no public reports referencing their exploitation in the wild, while also noting eSentire reported on December 23, 2025 that a detailed proof-of-concept exploit for CVE-2025-37164 had been released. Under BOD 22-01, FCEB agencies were recommended to apply the necessary fixes by January 28, 2026.

In a separate section, the report cited Check Point as identifying an active, large-scale exploitation campaign targeting CVE-2025-37164 that delivered the RondoDox botnet. It said Check Point reported the activity to CISA on January 7, 2026, and that this helped prompt inclusion in the KEV catalog the same day. Check Point said it observed more than 40,000 attack attempts between 05:45 and 09:20 UTC on January 7, 2026, and assessed the activity as automated, botnet-driven exploitation.

Gogs flaw flagged amid active exploitation

CISA also warned of active exploitation of a high-severity security flaw affecting Gogs by adding it to the KEV catalog, with the issue tracked as CVE-2025-8110. CISA described it as a path traversal vulnerability tied to improper symbolic link handling in the PutContents API that could allow code execution.

One account said details came to light when Wiz reported it being exploited in zero-day attacks, and described a technique involving a Git repository, a committed symbolic link pointing to a sensitive target, and use of the PutContents API to write data through the symlink so the operating system overwrites a file outside the repository. That description said an attacker could overwrite Git configuration files, including an sshCommand setting, to gain code execution privileges. The same report said Wiz identified 700 compromised Gogs instances, and cited Censys data saying there are over 1,600 internet-exposed Gogs servers, with the largest number located in China.

A separate report also described CVE-2025-8110 as a symlink bypass of a previously patched remote code execution issue tracked as CVE-2024-55947, and said Wiz Research identified over 700 compromised public-facing instances. That source said the earlier fix added path validation but did not check for symbolic links, enabling the bypass via Git’s symlink feature and allowing writes to targets such as “.git/config.”

The two accounts differed on patch status: one said there were currently no patches addressing CVE-2025-8110, while noting pull requests indicating necessary code changes and a maintainer comment that future images would include a patch once built on main. The other said the flaw was “addressed a week later” after Wiz found it during investigation of a malware incident. In the absence of a fix, guidance included disabling default open registration and limiting server access using a VPN or an allow-list, and FCEB agencies were required to apply mitigations by February 2, 2026.

Cisco Unified CM zero-day added

CISA also added a critical remote code execution vulnerability affecting Cisco Unified Communications Manager to the KEV catalog, with the issue tracked as CVE-2026-20045. The vulnerability was described as enabling attackers to execute arbitrary code on affected systems and escalate privileges to root level, with the weakness tied to improper code injection validation. The report said affected products include Cisco Unified Communications Manager (Unified CM), Unified CM Session Management Edition, Unified CM IM & Presence Service, Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance.

According to that report, CISA added CVE-2026-20045 to the KEV catalog on January 21, 2026, and set a mandatory remediation deadline of February 11, 2026. It also said the precise attack vector had not been publicly disclosed, while CISA’s KEV addition confirms active exploitation in the wild. The same account said the vulnerability had not been linked to ransomware campaigns at the time of writing.

TAGGED: CISA, cybersecurity, eslint-config-prettier, Gogs, HPE OneView, KEV catalog, Versa Concerto, Vite, Zimbra
Share This Article
Facebook Twitter Whatsapp Whatsapp Telegram Copy Link
By Rakesh Paul
I'm the Co-Founder of VellaTimes and an experienced digital marketer. With substantial experience in the blogging industry, I love crafting insightful and engaging news articles on technology, sports, and automobiles.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Read

OpenAI Seeks Nvidia AI Chip Alternatives

February 3, 2026

Denmark Election: PM Calls March 24 Vote Over Greenland

February 27, 2026

OpenAI accuses DeepSeek of distilling AI models to gain edge

February 15, 2026

Senate Rejects Iran War Powers Resolution, Backing Trump’s Military Campaign

March 5, 2026

Israel cuts ties with UN agencies after US withdrawal

January 14, 2026

Engineered blood vessels lead to new vascular disease treatments

February 12, 2026

Related News

A highly detailed rendering of the SMILE satellite orbiting Earth, with its solar panels deployed and the northern lights glowing in the background.
News

SMILE Mission Launch: Satellite Prepares for Space

Nisha Pradhan Nisha Pradhan March 22, 2026
A sleek modern laptop displaying the Windows 11 desktop in a softly lit contemporary office setting, representing Microsoft's latest performance updates.
News

Microsoft Reduces Windows 11 Copilot AI for Performance

Sameer Katoch Sameer Katoch March 22, 2026
A modern laptop displaying the Windows desktop on a brightly lit office desk.
News

Windows 11 Update: Microsoft Cuts AI Bloat to Boost Speed

Rakesh Paul Rakesh Paul March 22, 2026

About Us

VellaTimesVellaTimesVellaTimes

VellaTimes is a leading news portal that covers the latest trending news in technology, lifestyle, entertainment, automobiles, travel, and sports.

Explore

  • News
  • Technology
  • AI
  • Science
  • World

Useful Links

  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy

Subscribe Us

Subscribe to our newsletter for the Latest News and Top Stories!

© 2022 VellaTimes • All Rights Reserved.
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
adbanner
AdBlocker Detected
Our site is an advertising supported site. Please whitelist us to support our work.
Okay, I'll Whitelist