Known exploited vulnerabilities are security flaws that trusted authorities or threat intelligence confirm are under active attack, and they matter because enterprises use them to prioritize remediation, demonstrate risk-based patching, and align with regulatory and governance expectations.
Related Signals
177 articles about Known Exploited Vulnerabilities
CISA updated its alert to include two vulnerabilities, CVE-2025-64446 and CVE-2025-58034, affecting Fortinet FortiWeb web application firewalls. Exploitation of these could lead to unauthenticated remote code execution. Fortinet recommends upgrading to specified versions or disabling HTTP/HTTPS access for internet-facing interfaces.
CISA added a new vulnerability, CVE-2025-61757, involving missing authentication in Oracle Fusion Middleware, to its Known Exploited Vulnerabilities Catalog due to active exploitation. Federal agencies must remediate it per Binding Operational Directive 22-01. CISA urges all organizations to prioritize addressing such vulnerabilities.
CISA includes CVE-2021-26829 OpenPLC ScadaBR XSS vulnerability in its Known Exploited Vulnerabilities Catalog following reports of active exploitation.
CISA has updated its Known Exploited Vulnerabilities Catalog with three new vulnerabilities under active exploitation, urging organizations to prioritize timely remediation to reduce cyberattack risks. The updates relate to vulnerabilities in WatchGuard Firebox, Gladinet Triofox, and Microsoft Windows.
CISA has added five vulnerabilities with evidence of active exploitation to its Known Exploited Vulnerabilities Catalog, urging federal agencies and organizations to prioritize remediation to reduce cyberattack exposure.
Microsoft released an out-of-band security update to address a critical remote code execution vulnerability in Windows Server Update Service (WSUS) affecting multiple Windows Server versions. CISA advises organizations to identify vulnerable servers, apply the update, monitor for exploit activity, and use mitigations if updates cannot be applied immediately.