logo

CISA Alerts on Active Exploitation of Flaws in Fortinet, Ivanti, and Nice Products

ID: d3dfccd5-495d-5aed-a256-cba436f552a2

STIX ID: report--d3dfccd5-495d-5aed-a256-cba436f552a2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added three high-severity flaws to its Known Exploited Vulnerabilities catalog — CVE-2023-48788 (Fortinet FortiClient EMS SQLi, CVSS 9.3), CVE-2021-44529 (Ivanti EPM CSA code injection, CVSS 9.8), and CVE-2019-7256 (Nice Linear eMerge E3 OS command injection, CVSS 10.0) — noting evidence of active exploitation for at least Fortinet and Nice; federal agencies are required to apply mitigations by April 15, 2024, and authorities urge vendors to eliminate SQL injection defects through secure coding practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.