logo

CISA Adds Five Enterprise Software Flaws to Known Exploited Vulnerabilities Catalog

ID: 09c822e2-307d-56cd-bebc-0fe6dffc641e

STIX ID: report--09c822e2-307d-56cd-bebc-0fe6dffc641e

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-01-23

Date Updated: 2026-05-05

Author: Paul Shread

...
...

CISA added five enterprise software vulnerabilities to its Known Exploited Vulnerabilities catalog — high-severity flaws in Versa Concerto (improper authentication), VMware vCenter (out-of-bounds/heap overflow that may allow RCE), Zimbra Webmail (LFI), a supply-chain compromise in eslint-config-prettier that can execute malware on Windows, and an improper access control issue in Vite — highlighting significant attack vectors though CISA did not attribute exploitation to specific actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.