U.S. CISA adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalog
ID: d1cf7793-a9a0-5d69-9ef4-1ae31bcbb0a1
STIX ID: report--d1cf7793-a9a0-5d69-9ef4-1ae31bcbb0a1
Feed Name: Security Affairs
CISA added four high‑severity vulnerabilities — SolarWinds Web Help Desk deserialization RCE (CVE‑2025‑40551), GitLab SSRF (CVE‑2021‑39935), Sangoma FreePBX improper authentication (CVE‑2019‑19006), and FreePBX OS command injection (CVE‑2025‑64328) — to its Known Exploited Vulnerabilities catalog; several carry CVSS scores up to 9.8, there is evidence of active exploitation (notably SSRF activity), and federal agencies have been ordered to remediate the flaws on accelerated timelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
