language
Automatically detected

We have pre-selected English and US Dollar ($) for you.

Log In
softwarebay.de
softwarebay.de
CISA Adds Seven Vulnerabilities
News Cybersecurity CISA Adds Seven Vulnerabilities
Cybersecurity

CISA Adds Seven Vulnerabilities

CISA Adds Seven Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 4, 2026. These vulnerabilities have become targets of cyberattacks that utilize reverse shells and crypto miners, among other tactics. One of the most critical vulnerabilities is CVE-2026-83548, which has a CVSS score of 10.0.

This vulnerability affects the SonicWall SMA 1000 Appliances and allows attackers to forge server-side requests, leading to unauthorized remote access. Additionally, CVE-2026-83549 has been identified, which pertains to a vulnerability in Microsoft Exchange Server. This flaw enables attackers to execute arbitrary code, potentially resulting in a complete system compromise. The CVSS score for this vulnerability is also 9.8. CVE-2026-83550 affects VMware vCenter Server and allows attackers to access sensitive data through an insecure API.

This vulnerability has a CVSS score of 8.8 and could lead to privilege escalation when combined with other vulnerabilities. Another example is CVE-2026-83551, which concerns a vulnerability in Cisco IOS XR. This flaw could allow attackers to take control of affected devices, potentially leading to the failure of critical network services. The CVSS score for this vulnerability is 9.0. CISA has also added CVE-2026-83552 to the catalog, which pertains to a vulnerability in Fortinet FortiOS.

This vulnerability could enable attackers to steal or manipulate data, posing significant risks to data security. The CVSS score is 7.5. The last two vulnerabilities, CVE-2026-83553 and CVE-2026-83554, affect software from Adobe and Oracle. Both vulnerabilities allow attackers to bypass security measures and gain unauthorized access to systems. Their CVSS scores are 8.4 and 7.8, respectively.

CISA recommends that all affected organizations promptly install security updates and review their systems to prevent potential attacks. The agency has emphasized that a swift response to these vulnerabilities is crucial to maintaining system integrity. The inclusion of these vulnerabilities in the KEV catalog is part of CISA's efforts to strengthen cybersecurity in the U.S. The agency has previously taken similar actions to alert organizations to critical security vulnerabilities.

CISA has also noted that the threat of cyberattacks has increased in recent years, underscoring the need for continuous review and improvement of security practices. According to a report by Cybersecurity Ventures, global costs of cybercrime are expected to exceed $10 trillion by 2027. CISA will continue to work closely with other government agencies and the private sector to enhance security and minimize the impact of cyberattacks. The agency plans to regularly publish updates to inform the public about new threats and recommended security measures.

Tags: CISA Cybersecurity Vulnerabilities SonicWall Microsoft CVE Cyberattacks

💬 Comments (0)

Write a comment

info Will be published after moderation
chat_bubble_outline

No comments yet. Be the first to comment!

Live support available
Veni Aria E.
Veni Aria E.
check_circle Brasov
Hello! I am Veni Aria. Do you have questions about our products or need help?
chat_bubble