< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 14 sources · 19 days · First seen · Last updated

CISA vulnerability exploitation and patching directives

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued directives to federal agencies regarding multiple actively exploited software vulnerabilities. In late August 2026, CISA ordered the patching of two vulnerabilities in TrueConf Server video conferencing software. These flaws, identified as CVE-2026-72529 and CVE-2026-72530, reportedly allow unauthorized remote attackers to execute scripts and gain control of host systems. Reports indicate the Ukrainian hacktivist group ‘Head Mare’ has utilized these flaws to deploy malware against energy, transport, and IT sectors in Russia and Belarus. Shortly thereafter, CISA added six more vulnerabilities to its Known Exploited Vulnerabilities catalog. This included a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway appliances (CVE-2026-8452), which researchers demonstrated could allow remote code execution as root. Threat actors have been observed using this flaw to deploy web shells. Additionally, the Chinese cybercrime group UAT-10147 has been linked to targeting global web servers in the education, media, technology, and gaming sectors using several of the newly cataloged vulnerabilities. On August 27, 2026, CISA expanded its catalog to include a Linux kernel flaw (CVE-2026-53362) in the IPv6 networking subsystem that allows for privilege escalation. The agency also flagged vulnerabilities in Microsoft SharePoint, Windows IKE Service Extensions, Broadcom VMware vCenter, and Apple macOS. Further advisories were issued for industrial control systems and operational technology, specifically targeting Xiiaozet LK100W devices, All-Line Equipment Fuel-Boss systems, and Rockwell Automation OTTO Fleet Manager. CISA Red Team tests identified security gaps in critical infrastructure where attackers successfully escalated privileges and moved laterally without triggering alerts. On September 9, 2026, CISA added new critical vulnerabilities to its catalog, including a high-severity flaw in Adobe Commerce and Magento (CVE-2026-75650). Known as ‘StyleSmuggler’, this vulnerability allows unauthenticated remote code execution and has been used since September 4 to deploy web shells and backdoors.

Entities

CISA · Microsoft · Kaspersky · N-able · Citrix

Timeline

  1. 3 days ago

    [TECHNOLOGY] 2 sources
    CISA adds Microsoft, Adobe, and N-able flaws to exploited vulnerabilities catalog

    CISA has added critical vulnerabilities in Microsoft Windows, Adobe Commerce, and N-able N-central to its Known Exploited Vulnerabilities catalog due to active real-world exploitation.

  2. 16 days ago

    [TECHNOLOGY] 10 sources
    CISA flags multiple actively exploited vulnerabilities in Linux, Citrix, and Microsoft software

    CISA has added multiple actively exploited vulnerabilities to its KEV catalog, including flaws in the Linux kernel, Citrix NetScaler, Microsoft SharePoint, VMware vCenter, and Apple macOS.

  3. 21 days ago

    [TECHNOLOGY] 5 sources
    CISA orders patching of exploited TrueConf vulnerabilities

    CISA has ordered U.S. federal agencies to patch two exploited vulnerabilities in TrueConf video conferencing software used by attackers to execute scripts and gain server control.

Sources

businesstechweekly.com · cybernoz.com · cybersecurity-news.de · dev.to · drweb.de · flagthis.com · gcn.com · invitehealth.substack.com · nhmlac.org · planningassociates.com.au · thehackernews.com · theregister.com · viakoo.com · vital.com

This summary has been updated 2 times: see revision history