Global NewsHigh Priority (9/10)Usa

CISA Warns of Exploited Vulnerabilities in Cisco, Kentico, and Zimbra

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added eight new flaws to its Known Exploited Vulnerabilities catalog, including actively exploited bugs in Kentico Xperience and Zimbra.

Key Points

  • CISA added eight new flaws to its Known Exploited Vulnerabilities catalog.
  • Critical vulnerabilities in Kentico Xperience and Zimbra are confirmed to be actively exploited in attacks.

Full Details

CISA's announcement warns organizations that previously disclosed security defects in these platforms have been weaponized in real-world attacks. The Zimbra vulnerability (CVE-2025-48700) is an XSS bug allowing JavaScript execution, while other critical flaws affect Quest KACE, JetBrains TeamCity, and PaperCut. This update expands the KEV catalog, urging immediate patching. The agency's warning highlights the active threat landscape for these specific products.

Why It Matters

Organizations using these platforms face immediate security risks and must prioritize patching to prevent potential data breaches or system compromises.

Sourcesecurityweek.com

Get stories like this delivered daily

AI-curated news, personalized to your interests. Zero noise.

Start 7-Day Free Trial →

More in Global News