← Back to list

A Week of CISA KEV Alerts and Widespread active exploits

Executive Summary

Loginsoft · 2026-04-17 11:07 · 0 claps · 4.3 min read
#cybersecurity #lovi #loginsoft #vulnerabilityintelligence #cisakev
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🥊 · Combat Sports

A Week of CISA KEV Alerts and Widespread active exploits

Executive Summary

The latest threat landscape update highlighted a surge in actively exploited vulnerabilities and evolving attacker tactics across widely used technologies. During the week, Cybersecurity and Infrastructure Security Agency (CISA) added nine vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, reflecting ongoing exploitation across enterprise software. Of these, six vulnerabilities were associated with Microsoft products, impacting Windows, Exchange Server, Office, SharePoint Server, and Visual Basic for Applications, while two affected Adobe Acrobat and Reader, and one targeted Fortinet FortiClient EMS. In parallel, active exploitation activity was observed in additional platforms, including Marimo, ShowDoc, and nginx-ui, indicating continued attacker focus on both enterprise and niche applications. Threat intelligence reporting further underscored the rapid evolution of adversary tradecraft, with Storm-1175 conducting high-velocity intrusion campaigns by chaining zero-day and N-day vulnerabilities to deploy ransomware within hours across multiple global sectors.

1. Trending / Critical Vulnerabilities

This period’s threat landscape saw multiple vulnerabilities added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog, reflecting continued active exploitation across enterprise software, endpoint management solutions, and widely deployed applications. These included CVE-2026–21643 in Fortinet FortiClient EMS, an SQL Injection vulnerability enabling unauthenticated remote code execution via crafted HTTP requests; CVE-2026–32201 in Microsoft SharePoint Server, an Improper Input Validation flaw exploited as a zero-day to perform spoofing attacks; CVE-2026–34621 in Adobe Acrobat and Reader, a Prototype Pollution vulnerability enabling arbitrary code execution; and legacy yet actively exploited issues such as CVE-2025–60710, CVE-2023–36424, CVE-2020–9715, CVE-2012–1854, and CVE-2009–0238, highlighting continued exploitation of long-standing weaknesses.

Beyond KEV additions, active exploitation was also observed across multiple platforms, including nginx-ui (CVE-2026–33032), where authentication bypass enabled full service takeover; Marimo (CVE-2026–39987), a pre-authentication RCE exposing interactive shells; and ShowDoc (CVE-2025–0520), an unrestricted file upload flaw exploited to deploy web shells. Additionally, CVE-2023–21529 in Microsoft Exchange Server continued to see active abuse, with threat actors leveraging it for initial access and ransomware deployment, demonstrating the persistent risk posed by both newly disclosed and long-standing vulnerabilities across diverse environments.

2. Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Cytellite telemetry during this period revealed sustained scanning and exploitation activity targeting network appliances, enterprise platforms, and internet-facing services, underscoring continued adversary focus on high-impact infrastructure. Confirmed in-the-wild exploitation included CVE-2025–5777 in Citrix NetScaler ADC and Gateway, an Out-of-Bounds Read vulnerability, and CVE-2025–31324 in SAP NetWeaver, an Unrestricted File Upload flaw enabling system compromise. Additional active exploitation was observed in CVE-2024–4577 in PHP CGI, an OS Command Injection vulnerability, and CVE-2024–3400 in Palo Alto Networks PAN-OS, where command injection in the GlobalProtect feature allowed execution of arbitrary commands. Further exploitation included CVE-2024–47176 in OpenPrinting CUPS, an Improper Input Validation flaw leading to remote code execution, and CVE-2023–4966, a buffer overflow vulnerability enabling sensitive information disclosure. Additional confirmed exploitation was observed in CVE-2023–38646 in Metabase, a Remote Code Execution vulnerability, and CVE-2023–33831 in FUXA, a Command Injection vulnerability enabling full system compromise. While not observed under active exploitation, CVE-2026–27944 in nginx-ui and CVE-2023–6549 in Citrix NetScaler ADC and Gateway remain critical due to their potential impact, including authentication bypass and denial-of-service conditions. Collectively, these findings highlight continued attacker focus on command injection, file upload abuse, memory corruption, and remote code execution across enterprise applications, network edge devices, and open-source platforms, reinforcing the need for timely patching, reduced exposure, and continuous monitoring.

3. Vulnerabilities Abused by Malware

Building on activity observed in the previous week, this period’s threat intelligence highlighted high-velocity intrusion operations and infrastructure-level attacks targeting internet-facing systems and network devices. According to Microsoft Threat Intelligence, the China-linked Storm-1175 exploited both zero-day and N-day vulnerabilities, including CVE-2025–10035 and CVE-2026–23760, to rapidly compromise systems across healthcare, education, and finance sectors. The campaigns enabled swift data exfiltration and deployment of Medusa ransomware, supported by persistence mechanisms such as web shells, credential theft, and the use of remote access tools like AnyDesk and ConnectWise ScreenConnect. This rapid exploitation cycle demonstrated the ability of attackers to operationalize vulnerabilities within hours of public disclosure.

4. OSS Trending vulnerabilities observed this week

This period’s open-source threat activity highlighted multiple vulnerabilities across widely used frameworks, backend platforms, and core system components, reinforcing ongoing risks within developer ecosystems and software supply chains. Notable issues included CVE-2026–23869 in the npm ecosystem, a Denial of Service vulnerability in React Server Components that could impact application availability; CVE-2026–33478 in the Packagist ecosystem, an Unauthenticated Remote Code Execution flaw in the WWBN AVideo Platform enabling full system compromise; CVE-2026–34486 in the Maven ecosystem, a Missing Encryption of Sensitive Data issue in Apache Tomcat that could lead to data exposure; CVE-2026–39890 in the PyPI ecosystem, a Deserialization of Untrusted Data vulnerability allowing arbitrary code execution; and CVE-2025–38352 in the Android ecosystem, a Race Condition flaw that may enable privilege escalation or system instability. Collectively, these findings underscore persistent security gaps in open-source dependencies and foundational systems, highlighting the need for continuous monitoring, secure coding practices, and timely patch management.

5. Pre-NVDs vulnerabilities observed this week

This period’s early vulnerability disclosures revealed multiple security issues across enterprise platforms, backend frameworks, and application components, highlighting emerging risks across both infrastructure and application layers. Notable findings included CVE-2026–33518 in ArcGIS Enterprise, an Incorrect Privilege Assignment vulnerability that could allow unauthorized privilege escalation; CVE-2026–40248 in free5GC, an Improper Path Validation flaw enabling unauthorized access to restricted file paths; CVE-2026–40255 in AdonisJS HTTP/Server, a URL Redirection to Untrusted Site vulnerability that could facilitate phishing or redirection attacks; CVE-2026–40319 in RegexMatching Check, a Regular Expression Denial of Service (ReDoS) issue capable of degrading service availability; and CVE-2026–40540 in DSM, an Information Disclosure vulnerability that could expose sensitive system data. Collectively, these findings highlight the continued emergence of diverse vulnerability classes across modern applications and infrastructure, reinforcing the importance of secure coding practices, validation mechanisms, and proactive vulnerability management.

Conclusion

The continued exploitation of both newly disclosed and long-standing vulnerabilities highlights a threat landscape where speed and adaptability define attacker success. The targeting of widely used platforms alongside niche tools demonstrates that no environment remains immune to compromise. Rapid weaponization and chaining of vulnerabilities, as seen in recent campaigns, significantly reduce the response window for defenders. This underscores the need for continuous monitoring, timely patching, and proactive threat intelligence to mitigate risk effectively. Platforms like Loginsoft Vulnerability Intelligence (LOVI) play a critical role in enabling organizations to detect, prioritize, and respond to emerging threats before they escalate into large-scale incidents.

For more details, check out the full report.


메타데이터
post_id
d5effb5ef402
slug
a-week-of-cisa-kev-alerts-and-widespread-active-exploits-d5effb5ef402
url
https://medium.com/@Loginsoft/a-week-of-cisa-kev-alerts-and-widespread-active-exploits-d5effb5ef402
canonical_url
https://medium.com/@Loginsoft/a-week-of-cisa-kev-alerts-and-widespread-active-exploits-d5effb5ef402
author_url
https://medium.com/@Loginsoft
status
ok
fetched_at
2026-06-20 20:29:01