Skip to content
tag — cisa-kev

grep -rl "cisa-kev" ./articles

#cisa-kev

14 articles

The NetScaler appliances restarting after the patch were not a patch bug — they were a third zero-day, and the sixth crash is the trigger

2026-10-06Security

On 3 October we wrote that Citrix customers were watching their gateways reboot after installing the emergency build, with no CVE and no root cause published. Citrix disclosed it on the 4th: CVE-2026-88779, a memory overflow reached through SAML, exploited in targeted attacks. Each attempt crashes the authentication service, and the sixth restarts the appliance.

8,393 Gitea servers are exposed, and the flaw needs an account anyone can make

2026-08-31Security

CVE-2026-60004 lets a user with ordinary write access to a repository run shell commands as the Gitea system user. That reads as an authenticated flaw until you notice that Gitea ships with open registration, so a visitor can sign up, create a repository, and qualify. The fix has been out since 27 July. Miners are already running.

A 2023 flaw with a 2023 fix was used to take nuclear-material records this year

2026-08-31Security

CVE-2023-49105 lets anyone read, change or delete files on an ownCloud server without authenticating, if they know a username and the default configuration is in place. It was fixed in November 2023. It has now been used against a Philippine nuclear research body, and CISA added it to its exploited-vulnerabilities list on 27 August.

Exploited since January, added to CISA's list in August, due in three days

2026-08-25Security

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.