CISA Adds Six Known Exploited Vulnerabilities to Catalog
TacitSoft analysis
CISA added six vulnerabilities to KEV, giving operators confirmed exploitation evidence that can move affected products ahead of ordinary remediation queues.
The governed signal set covers Apache APISIX identity and availability flaws, Ubiquiti fixes, Microsoft 365 session theft, CISA exploitation tracking, and malware activity across endpoints and infrastructure.
Ranked operator signal
Each item links to its publisher and includes one independently written TacitSoft sentence based on structured facts.
TacitSoft analysis
CISA added six vulnerabilities to KEV, giving operators confirmed exploitation evidence that can move affected products ahead of ordinary remediation queues.
TacitSoft analysis
CISA's Vulnerability Review gives operators an authoritative validation point for prioritization while product-specific advisories remain the source for exact remediation steps.
TacitSoft analysis
Ubiquiti has issued fixes for three maximum-severity vulnerabilities, establishing an urgent update baseline for operators running the affected products.
TacitSoft analysis
CVE-2026-75020 lets Apache APISIX LDAP authentication cross subtree boundaries, creating an identity-impersonation risk for deployments that separate users by directory scope.
TacitSoft analysis
Dark Caracal has expanded its cyber-espionage tooling with newly reported malware, increasing the range of payloads defenders may need to identify in the actor's targeting scope.
TacitSoft analysis
The FBI disrupted a proxy network linked to Chinese espionage operations, removing one infrastructure path while giving defenders a new basis for related traffic hunting.
TacitSoft analysis
NovaCookies campaigns are using genuine DocuSign notifications to reach Microsoft 365 session-theft flows, showing that a trusted sender path does not guarantee a safe authentication journey.
TacitSoft analysis
Android malware is abusing the update mechanism used by automotive head units, turning a trusted maintenance path into a potential delivery channel inside connected vehicles.
TacitSoft analysis
Nimbus Manticore now combines a TWOSTROKE-like backdoor with SSH tunneling, broadening the actor's options for persistent access and concealed command traffic.
TacitSoft analysis
A disclosed Emacs TRAMP behavior can trigger local command execution without an interactive click, making exposure review important wherever remote-file workflows are enabled.
TacitSoft analysis
CVE-2026-75005 exposes Apache APISIX to unauthenticated CPU exhaustion, putting gateway availability at risk before an attacker needs an established identity.
TacitSoft analysis
CVE-2026-74848 permits cross-user response poisoning through Apache APISIX serverless plugins, weakening isolation wherever multiple users share the same gateway path.
Choose daily, weekly, monthly, or any combination.