CISA Adds 4 Critical Flaws to “Must-Patch” List as Exploits Surge
ID: 3b646113-df8f-555d-b5b9-c05533a7b1ab
STIX ID: report--3b646113-df8f-555d-b5b9-c05533a7b1ab
Feed Name: securityonline.info
CISA added four actively weaponized vulnerabilities to its KEV catalog: a critical Traefik authentication bypass in Versa Concerto (CVE-2025-34026, CVSS 9.2) enabling access to administrative Actuator endpoints; a malicious code injection in eslint-config-prettier that executes node-gyp.dll on Windows during package install (CVE-2025-54313); a high-severity Local File Inclusion in Synacor Zimbra Webmail Classic (CVE-2025-68645, CVSS 8.8); and an improper access control in Vite exposing arbitrary file contents (CVE-2025-31125). Federal agencies are ordered to patch by February 12, 2026, and private organizations are urged to remediate immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
