Skip to content
.ca
sign in

Threat intelligence from CISA

117 reports on cyfar.ca summarizing CISA research. Visit CISA

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-35616, an improper access control vulnerability in Fortinet FortiClient EMS, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize the timely remediation of this vulnerability to reduce their exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-3502, a vulnerability in TrueConf Client involving the download of code without integrity checks, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to potential cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-5281, a Use-After-Free vulnerability in Google Dawn, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-3055, an actively exploited out-of-bounds read vulnerability affecting Citrix NetScaler, to its Known Exploited Vulnerabilities (KEV) Catalog. The agency mandates federal remediation under BOD 22-01 and strongly urges all organizations to prioritize patching to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reportcritical

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2025-53521, a Remote Code Execution vulnerability affecting F5 BIG-IP, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.

CISA4 months ago2 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security Trivy, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-33017, a code injection vulnerability affecting Langflow, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds Five Known Exploited Vulnerabilities to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with five new actively exploited vulnerabilities affecting Apple products, Craft CMS, and Laravel Livewire. Organizations are strongly urged to prioritize timely remediation of these flaws to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-20131, a deserialization of untrusted data vulnerability affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC), to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.

CISA4 months ago4 minLLM reporthigh

CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization

CISA has issued an alert regarding malicious cyber activity targeting endpoint management systems, specifically highlighting a recent attack on Stryker Corporation's Microsoft environment. The alert strongly urges organizations to harden Microsoft Intune and similar platforms by enforcing least privilege, phishing-resistant MFA, and Multi Admin Approval to prevent unauthorized high-impact administrative actions.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-20963, a Microsoft SharePoint Deserialization of Untrusted Data Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation of this flaw as part of their vulnerability management practices to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize timely remediation of this vulnerability to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2025-68613, an Improper Control of Dynamically-Managed Code Resources vulnerability in n8n, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation to reduce exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three actively exploited vulnerabilities affecting Omnissa Workspace ONE, SolarWinds Web Help Desk, and Ivanti Endpoint Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to apply patches immediately to mitigate the risk of compromise.

CISA4 months ago3 minLLM reporthigh

CISA Adds Five Known Exploited Vulnerabilities to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with five additional flaws affecting Hikvision, Rockwell, and Apple products based on evidence of active exploitation. Organizations, particularly federal agencies under BOD 22-01, are urged to prioritize remediation to reduce their exposure to cyberattacks.

CISA4 months ago3 minLLM reporthigh

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two actively exploited vulnerabilities, CVE-2026-21385 (Qualcomm Memory Corruption) and CVE-2026-22719 (VMware Aria Operations Command Injection), to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these flaws to reduce exposure to cyberattacks.