CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
ID: d2293e20-b430-5b4b-9876-facd0af6d99e
STIX ID: report--d2293e20-b430-5b4b-9876-facd0af6d99e
Feed Name: The Hacker News
Threat Score
CISA added three actively exploited vulnerabilities to its KEV catalog — CVE-2021-22054 (SSRF in Omnissa/Workspace One UEM), CVE-2025-26399 (critical deserialization bug in SolarWinds Web Help Desk linked to Warlock ransomware activity), and CVE-2026-1603 (Ivanti Endpoint Manager authentication bypass with exploitation status unknown) — and mandated federal patching with imminent deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
