logo

CISA confirms active exploitation of four enterprise software bugs

ID: 42a61e05-26aa-53c7-96c0-794f545be277

STIX ID: report--42a61e05-26aa-53c7-96c0-794f545be277

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** CISA confirmed active exploitation of four distinct vulnerabilities — a critical authentication bypass in Versa Concerto, a local file inclusion in Zimbra Webmail Classic, an improper access control issue in Vite dev instances, and a supply‑chain compromise of eslint-config-prettier that distributed a Windows token‑stealing payload — and added them to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch or mitigate by 2026‑02‑12.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.