GeoServer CVE-2025-58360 added to CISA KEV

GeoServer CVE-2025-58360 added to CISA KEV

Why this vulnerability matters CVE-2025-58360 is a recently disclosed XML External Entity (XXE) vulnerability in OSGeo GeoServer that has now been added to the CISA Known Exploited Vulnerabilities (KEV) catalog,…
CVE-2025-6218 and CVE-2025-62221 Hit CISA KEV

CVE-2025-6218 and CVE-2025-62221 Hit CISA KEV

CISA has added CVE-2025-6218 and CVE-2025-62221 to its Known Exploited Vulnerabilities (KEV) catalog, signaling active real-world exploitation and immediate remediation requirements for federal agencies and private sector organizations. These flaws…
Android Framework Zero-Days Hit CISA KEV

Android Framework Zero-Days Hit CISA KEV

CISA added two high-severity Android Framework vulnerabilities—CVE-2025-48572 and CVE-2025-48633—to its Known Exploited Vulnerabilities (KEV) catalog on December 1, 2025, confirming limited, targeted exploitation in the wild. These zero-days, addressed in…
CISA KEV Catalog Update November 2025

CISA KEV Catalog Update November 2025

The following vulnerabilities were recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog and involve WatchGuard Firebox, Microsoft Windows, and Gladinet Triofox products: WatchGuard Firebox CVE-2025-9242: Out-of-Bounds Write VulnerabilityThis…
CISA adds Magento and WSUS bugs to KEV Catalog

CISA adds Magento and WSUS bugs to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two high‑severity vulnerabilities — one in Microsoft Windows Server Update Services (WSUS) and another in Adobe Commerce/Magento Open Source…