Active Exploitation Risks: CISA Adds 4 Critical Vulnerabilities
ID: 86eb1833-15a9-531e-bc00-7ec3864f9b2f
STIX ID: report--86eb1833-15a9-531e-bc00-7ec3864f9b2f
Feed Name: Cyble Blog
Threat Score
**Executive Summary:** CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog — two critical Zyxel DSL command-injection flaws (CVE-2024-40891, CVE-2024-40890) reportedly under active exploitation, and two Windows privilege-elevation/overflow issues (CVE-2025-21418, CVE-2025-21391); organizations and users are advised to apply vendor patches and firmware updates immediately to prevent device compromise and privilege escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
