logo

CISA Adds 4 Critical Flaws to “Must-Patch” List as Exploits Surge

ID: 3b646113-df8f-555d-b5b9-c05533a7b1ab

STIX ID: report--3b646113-df8f-555d-b5b9-c05533a7b1ab

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA added four actively weaponized vulnerabilities to its KEV catalog: a critical Traefik authentication bypass in Versa Concerto (CVE-2025-34026, CVSS 9.2) enabling access to administrative Actuator endpoints; a malicious code injection in eslint-config-prettier that executes node-gyp.dll on Windows during package install (CVE-2025-54313); a high-severity Local File Inclusion in Synacor Zimbra Webmail Classic (CVE-2025-68645, CVSS 8.8); and an improper access control in Vite exposing arbitrary file contents (CVE-2025-31125). Federal agencies are ordered to patch by February 12, 2026, and private organizations are urged to remediate immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.