Safeguard
Tag

cisa-kev

Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Vulnerability Analysis

Notepad++'s Own Updater Had No Cryptographic Integrity Check

CVE-2025-15556 let an attacker who intercepts update traffic serve a malicious installer that Notepad++'s WinGUp updater would execute unverified — in one of the most widely installed Windows utilities.

Sep 16, 20264 min read
Vulnerability Analysis

Dell RecoverPoint's Perfect-10 Bug Was a Zero-Day Before It Was a Patch

CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.

Sep 16, 20264 min read
Vulnerability Analysis

How Apache ActiveMQ's Monitoring Bridge Became a Remote Code Execution Path

CVE-2026-34197 turns ActiveMQ's Jolokia JMX-HTTP bridge into a code execution chain, exploiting an ordering flaw where Spring instantiates beans before the broker validates configuration.

Sep 16, 20264 min read
Vulnerability Analysis

A Second PaperCut Authentication Bypass, This One Tied to Ransomware

CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.

Sep 16, 20264 min read
Vulnerability Analysis

Two 2021 ScadaBR Bugs Take Four Years to Reach Confirmed Exploitation

An unrestricted JSP upload and a stored XSS bug in OpenPLC's ScadaBR, both disclosed the same day in 2021, were confirmed exploited within a week of each other in late 2025.

Sep 16, 20265 min read
Vulnerability Analysis

Roundcube's Same-Day KEV Entries: A 9.9 Deserialization Bug and an SVG XSS Foothold

A near-maximum-severity PHP deserialization RCE and a stored XSS bug via SVG animate tags landed in CISA's KEV catalogue on the same date, describing a realistic foothold-to-RCE chain.

Sep 16, 20265 min read
Vulnerability Analysis

Zimbra's Classic Web Client Produced Five Confirmed-Exploited CVEs

From a 2020 SSRF bug to three related XSS bypasses and an unauthenticated file-inclusion flaw, five Synacor Zimbra vulnerabilities were confirmed exploited within a single KEV window.

Sep 16, 20265 min read
Vulnerability Analysis

WinRAR, FileZen, and IGEL OS: Three Unrelated Products, Three Broken Trust Boundaries

An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.

Sep 16, 20265 min read
Vulnerability Analysis

Metro4Shell: React Native's Development Server Exposed to Anyone on the Network

CVE-2025-11953 lets unauthenticated attackers run arbitrary commands on developer machines through React Native's Metro Development Server, which binds to external interfaces by default.

Sep 16, 20265 min read
Vulnerability Analysis

TrueConf's Update Mechanism Had No Integrity Check, and a Nation-State Actor Found It

CVE-2026-3502, a separate TrueConf Client finding beyond this series' earlier coverage, let attackers substitute tampered update payloads, tied to Operation TrueChaos against Southeast Asian governments.

Sep 16, 20264 min read
Vulnerability Analysis

A Read-Only API Key Was Enough to Overwrite Files on Cisco SD-WAN Manager

CVE-2026-20122, an additional Cisco Catalyst SD-WAN Manager finding beyond this series' earlier coverage, shows how a low-privilege API credential can still enable a file-write escalation.

Sep 16, 20264 min read
Vulnerability Analysis

Five Years of DELMIA Apriso Releases Share the Same Two Confirmed-Exploited Bugs

A missing authorization flaw and a code injection vulnerability in Dassault Systèmes' manufacturing execution system span every release from 2020 through 2025.

Sep 16, 20264 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.