logo

CISA tags Windows, Cisco vulnerabilities as actively exploited

ID: 71fc7f2e-ab2d-5b09-9c46-d679e08ed322

STIX ID: report--71fc7f2e-ab2d-5b09-9c46-d679e08ed322

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-03

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

**Executive summary:** CISA has added two actively exploited vulnerabilities—CVE-2023-20118 impacting Cisco RV-series VPN routers (which can be chained with CVE-2023-20025 for full takeover) and CVE-2018-8639, a Win32k elevation-of-privilege affecting Windows clients and servers—to its Known Exploited Vulnerabilities catalog and directed federal agencies to patch within a mandated timeframe; the advisory notes active exploitation but does not attribute activity or provide exploit details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.