cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Two More FreePBX CVEs, Six Years Apart, Confirmed Exploited on the Same Day
A 2025 command injection bug in FreePBX's Endpoint Manager and a 2019 authentication bypass landed in KEV together, additional findings beyond FreePBX coverage published elsewhere in this series.
Gladinet CentreStack and Triofox: A Hardcoded Key, an Exposed Setup Page, and an Unauthenticated LFI
Three confirmed-exploited Gladinet vulnerabilities that NVD itself says can be chained together into full system compromise across CentreStack and Triofox.
Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component
Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.
ThreatSonar, Control Web Panel, and XWiki: When Under-the-Radar Software Gets Popped
An unauthenticated eval injection in XWiki, a known-username command injection in Control Web Panel, and a file-upload RCE in an anti-ransomware tool itself — three vendors, one lesson.
BeyondTrust Remote Support's Pre-Auth Command Injection Is a Ransomware Vector
CVE-2026-1731 lets an unauthenticated attacker run OS commands on BeyondTrust Remote Support and Privileged Remote Access, with CISA confirming active ransomware use.
JetBrains TeamCity's Path Traversal Bug Is Now Tied to Ransomware
CVE-2024-27199, a relative path traversal in TeamCity enabling limited admin actions, carries CISA's confirmed ransomware flag — a reminder that CI/CD servers are a supply-chain target.
A Perfect-10 Authentication Bypass in Quest's Endpoint Management Appliance
CVE-2025-32975 lets an attacker impersonate any user of Quest KACE Systems Management Appliance without valid credentials, reaching complete administrative takeover.
WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware
Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.
Two More GitLab SSRF Bugs, Reached Through Webhooks and the CI Lint API
An additional pair of GitLab server-side request forgery vulnerabilities, distinct from the CVE covered earlier in this series, both confirmed exploited within weeks of each other.
Adobe Commerce and Experience Manager Forms: Two Critical RCEs in the Same Ten Days
A perfect-10 code execution bug in AEM Forms and a 9.1 session-takeover flaw in Commerce and Magento both entered CISA's KEV catalogue within days of each other in October 2025.
Three Adobe Acrobat and Reader Bugs, From a 2009 Overflow to This Year's Prototype Pollution
A heap overflow first exploited in 2009, a use-after-free from 2020, and a fresh prototype pollution bug — all three confirmed exploited against Adobe Acrobat and Reader within weeks of each other.
A VPN Gateway and an Endpoint Manager, Both Compromised by Trusting Remote Input
Array Networks' ArrayOS AG command injection and Motex LANSCOPE's communication-channel verification flaw are unrelated products that share the same structural weakness: infrastructure built to be trusted rather than to verify.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.