Skip to content

Topic

Actively Exploited Vulnerabilities and KEV Mandates

Topic tracking vulnerabilities under active exploitation, CISA's KEV catalog additions, and mandated federal remediation deadlines.

Current stories

securityConfirmed2 publishers

Attackers chain two unpatched AhsayCBS flaws to plant webshells on MSP backup servers

Attackers are chaining two unpatched AhsayCBS flaws to run code as SYSTEM and plant webshells and XMRig miners, according to Huntress. Managed service providers are the main users of the console, so the hosts being hit are the ones that manage backup users and policies for clients.

Reality

Evidence68
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence66
securityConfirmed4 publishers

China-based actor targets U.S. Rejetto HFS servers through a forgeable admin cookie

VulnCheck says a China-based actor began targeting vulnerable U.S. Rejetto HFS servers on October 1, exploiting CVE-2026-61500 to forge admin sessions. The fix shipped in July as version 3.2.1. Exposed instances that have not updated are reachable now.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 47%
Investor
Investor 10%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives50
Confidence60
buildOne report1 publisher

F5 and Cisco report live exploitation in two of the three security products Canada's Cyber Centre flagged

F5 and Cisco say attackers are exploiting flaws in BIG-IP APM and ISE, two of the three security products in Canada's September 2026 Cyber Centre alerts. Three alerts are too few to show a trend in attacker targeting, but the two exploited products need fixed software now.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence50
securityConfirmed4 publishers

Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection

Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence55
Adoption30
Hype gap+25
Incentives
Insufficient
Confidence60
securityConfirmed4 publishers

Attackers are exploiting CVE-2026-93952 in VeloCloud Orchestrators that authenticate Edges by certificate

Arista says the pre-authentication flaw is already being used against on-premises orchestrators that issue certificates to their Edge devices, and the fixed build an operator needs may not exist for their release train yet.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence80
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence75