cisa-kev
Safeguard articles tagged "cisa-kev" — guides, analysis, and best practices for software supply chain and application security.
100 articles
SimpleHelp's Two Confirmed-Exploited Bugs Form a Complete Ransomware Attack Chain
A missing authorization flaw and a path traversal RCE in SimpleHelp remote support software, both confirmed for Medusa and DragonForce ransomware operations.
LiteSpeed's cPanel Plugin: A Symlink Escape and a Root Privilege Escalation, Weeks Apart
Two LiteSpeed cPanel plugin vulnerabilities confirmed exploited in May 2026 form a plausible escalation chain from any tenant account to root on shared hosting infrastructure.
Samsung's Year: A Signage Server Bug and a Codec Library Hit Twice for Spyware
Three confirmed-exploited Samsung vulnerabilities span an enterprise digital signage server and a mobile image codec library hit twice in five months, one tied to commercial-grade Android spyware.
A 2016 SKYSEA Client View Bug Was Confirmed Exploited Nine Years Later
CVE-2016-7836, a critical authentication flaw in a Japanese endpoint management console, sat disclosed for nearly a decade before CISA confirmed active exploitation in October 2025.
GeoServer's WMS Endpoint Adds Another XXE to Its Exploitation History
CVE-2025-58360 lets attackers define external XML entities through GeoServer's GetMap operation — the latest confirmed-exploited bug in a geospatial server long favored by less security-mature operators.
F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem
A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.
Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability
Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.
Two PAN-OS Vulnerabilities Target Palo Alto's Front Doors: GlobalProtect and Captive Portal
A root-privilege buffer overflow in the User-ID Authentication Portal and a GlobalProtect authentication bypass confirmed for ransomware use, both hitting PAN-OS's remote-access surface within weeks of each other.
Android Framework and Qualcomm Chipsets: Four CVEs Across the Mobile Stack
Three Android Framework privilege-escalation bugs and a Qualcomm chipset memory corruption flaw, confirmed exploited across the software and silicon layers of the Android ecosystem.
From a 2010 Firefox Bug to a 2025 Vite Dev-Server Flaw: Four Unrelated Products, One Lesson
An industrial controller authentication bypass, an EoL cellular gateway RCE, a fifteen-year-old browser bug, and a Vite dev-server exposure — none related, all confirmed exploited.
How a Non-Atomic Credential Rotation Let Attackers Take Over 76 Trivy Action Tags
A compromised-credential attack on Aquasecurity's Trivy scanner force-pushed malware into version tags across trivy-action and setup-trivy, exploiting the gap left by an earlier, incomplete rotation.
The ConnectWise ScreenConnect Path Traversal Bug Behind Storm-1175's Medusa Ransomware Runs
CVE-2024-1708 carries CISA's known-ransomware-use designation, tied directly to Storm-1175's high-tempo Medusa ransomware operations against unpatched, internet-facing RMM instances.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.