cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Notepad++'s Own Updater Had No Cryptographic Integrity Check
CVE-2025-15556 let an attacker who intercepts update traffic serve a malicious installer that Notepad++'s WinGUp updater would execute unverified — in one of the most widely installed Windows utilities.
Dell RecoverPoint's Perfect-10 Bug Was a Zero-Day Before It Was a Patch
CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.
How Apache ActiveMQ's Monitoring Bridge Became a Remote Code Execution Path
CVE-2026-34197 turns ActiveMQ's Jolokia JMX-HTTP bridge into a code execution chain, exploiting an ordering flaw where Spring instantiates beans before the broker validates configuration.
A Second PaperCut Authentication Bypass, This One Tied to Ransomware
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
Two 2021 ScadaBR Bugs Take Four Years to Reach Confirmed Exploitation
An unrestricted JSP upload and a stored XSS bug in OpenPLC's ScadaBR, both disclosed the same day in 2021, were confirmed exploited within a week of each other in late 2025.
Roundcube's Same-Day KEV Entries: A 9.9 Deserialization Bug and an SVG XSS Foothold
A near-maximum-severity PHP deserialization RCE and a stored XSS bug via SVG animate tags landed in CISA's KEV catalogue on the same date, describing a realistic foothold-to-RCE chain.
Zimbra's Classic Web Client Produced Five Confirmed-Exploited CVEs
From a 2020 SSRF bug to three related XSS bypasses and an unauthenticated file-inclusion flaw, five Synacor Zimbra vulnerabilities were confirmed exploited within a single KEV window.
WinRAR, FileZen, and IGEL OS: Three Unrelated Products, Three Broken Trust Boundaries
An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.
Metro4Shell: React Native's Development Server Exposed to Anyone on the Network
CVE-2025-11953 lets unauthenticated attackers run arbitrary commands on developer machines through React Native's Metro Development Server, which binds to external interfaces by default.
TrueConf's Update Mechanism Had No Integrity Check, and a Nation-State Actor Found It
CVE-2026-3502, a separate TrueConf Client finding beyond this series' earlier coverage, let attackers substitute tampered update payloads, tied to Operation TrueChaos against Southeast Asian governments.
A Read-Only API Key Was Enough to Overwrite Files on Cisco SD-WAN Manager
CVE-2026-20122, an additional Cisco Catalyst SD-WAN Manager finding beyond this series' earlier coverage, shows how a low-privilege API credential can still enable a file-write escalation.
Five Years of DELMIA Apriso Releases Share the Same Two Confirmed-Exploited Bugs
A missing authorization flaw and a code injection vulnerability in Dassault Systèmes' manufacturing execution system span every release from 2020 through 2025.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.