logo

The ‘Must-Patch’ List: CISA Adds Actively Exploited SolarWinds, Ivanti, and Omnissa Flaws to KEV

ID: 19543852-106d-5704-8c0d-973321954337

STIX ID: report--19543852-106d-5704-8c0d-973321954337

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA has added three high-risk vulnerabilities to its Known Exploited Vulnerabilities catalog—an authentication-bypass SSRF in VMware/Omnissa Workspace ONE (CVE-2021-22054), a critical deserialization remote code execution in SolarWinds Web Help Desk (CVE-2025-26399, CVSS 9.8), and an Ivanti Endpoint Manager credential-leak authentication bypass (CVE-2026-1603, CVSS 8.6)—noting active exploitation and urging immediate patching under federal remediation directives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.