#cisakev

16 posts · Last used 8d

🔴 EXPLOITED CVE-2025-25249: A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthorized code execution via crafted packets. It is listed in CISA KEV. Affected: FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 and 7.2 branches. Fix: upgrade to the patched releases. CISA due date September 12, 2026. https://www.cve.org/CVERecord?id=CVE-2025-25249 #CISAKEV #infosec #cybersecurity
0
0
0
0
🔴 EXPLOITED Cisco Secure Firewall Management Center ships a hardcoded password that lets a stranger log in with no credentials (CVE-2026-20316). It is being exploited now and sits on CISA's must-patch list. Apply the hotfix, then check logs for signs of entry. https://suriq.io/blog/cisco-fmc-hardcoded-password-cve-2026-20316 #CVE #Detection #CISAKEV #infosec
0
0
0
0
🔴 EXPLOITED CISA just flagged a Fortinet firewall flaw as actively exploited. CVE-2025-68686 bypasses the fix meant to kick attackers out of hacked FortiGates. They keep reading the device's files. Patch FortiOS to 7.6.2 or 7.4.7, then rotate secrets. https://suriq.io/blog/fortios-symlink-patch-bypass-cve-2025-68686-kev #CISAKEV #infosec #cybersecurity
0
0
0
0
🔴 EXPLOITED Check Point's SmartConsole flaw (CVE-2026-16232) lets an unauthenticated attacker log in as full admin. It is being exploited now. Affects Security Management servers reachable over the network. Fix: limit management access to your admin IPs, then patch. https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited #CVE #Phishing #CISAKEV #infosec
0
0
0
0
🔴 EXPLOITED Two Joomla page builders have CVSS-10 flaws that let anyone upload a webshell with no login: SP Page Builder and Page Builder CK. Both are exploited and on CISA's KEV list. Patch, then hunt: the fix won't remove the rogue admin it leaves behind. https://suriq.io/blog/joomla-page-builder-uploads-exploited-kev #CVE #CISAKEV #infosec #cybersecurity
0
0
0
0
You've seen all posts