Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Exploited Vulnerabilities in Key Software

CISA Highlights Exploited Vulnerabilities in Key Software

Posted on March 10, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new alert concerning vulnerabilities in prominent software systems, highlighting their active exploitation by cyber attackers. On Monday, CISA updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical security flaws, emphasizing the urgency for organizations to address these weaknesses.

Critical Vulnerabilities Identified

The vulnerabilities added to the KEV catalog involve software from Omnissa Workspace One, SolarWinds, and Ivanti. Specifically, CVE-2021-22054 affects the Workspace One UEM, presenting a server-side request forgery (SSRF) issue that can be exploited to gain unauthorized access to sensitive data. Another significant flaw, CVE-2025-26399, impacts the SolarWinds Web Help Desk, allowing attackers to execute commands via deserialization of untrusted data. Furthermore, CVE-2026-1603 in Ivanti Endpoint Manager can lead to credential leakage due to an authentication bypass vulnerability.

Exploitation Evidence and Threat Response

Microsoft and Huntress have reported active exploitation of the SolarWinds vulnerability by threat actors, suspected to be the Warlock ransomware group. Additionally, the SSRF vulnerability in Workspace One was previously identified by GreyNoise as part of a broader exploit campaign. Currently, there is limited information on the active exploitation of the Ivanti vulnerability, and its security bulletin remains unupdated in this regard.

Federal Response and Security Measures

In response to these threats, CISA has directed Federal Civilian Executive Branch (FCEB) agencies to mitigate risks by applying necessary patches. Agencies are required to address the SolarWinds Web Help Desk vulnerability by March 12, 2026, and complete updates for the Workspace One and Ivanti vulnerabilities by March 23, 2026. These measures are critical to safeguarding federal systems from potential breaches.

CISA underscores the significance of these vulnerabilities as frequent targets for cyber attackers, posing elevated risks to federal operations. Organizations are encouraged to prioritize these updates to fortify their cybersecurity defenses against ongoing threats.

The Hacker News Tags:CISA, cyber threats, Cybersecurity, exploited vulnerabilities, federal security, Ivanti, security flaws, SolarWinds, Vulnerabilities, Workspace One

Post navigation

Previous Post: Malware Disguised as Teams and Zoom Apps Targets Enterprises
Next Post: Anthropic Challenges U.S. ‘Supply Chain Risk’ Designation

Related Posts

Microsoft Unveils DNS ClickFix Attack Using Nslookup Microsoft Unveils DNS ClickFix Attack Using Nslookup The Hacker News
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware The Hacker News
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems The Hacker News
38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases The Hacker News
Post-Quantum Cryptography and AI Vulnerabilities: A Security Update Post-Quantum Cryptography and AI Vulnerabilities: A Security Update The Hacker News
Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Fixes Vulnerability in Entra Agent ID Administration
  • CISA Highlights New Security Flaws, Sets 2026 Deadline
  • Hackers Target Cisco Devices with Known Vulnerabilities
  • ADT Faces Data Breach After ShinyHunters Claim
  • Chinese Hackers Exploit Routers for Hidden Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Fixes Vulnerability in Entra Agent ID Administration
  • CISA Highlights New Security Flaws, Sets 2026 Deadline
  • Hackers Target Cisco Devices with Known Vulnerabilities
  • ADT Faces Data Breach After ShinyHunters Claim
  • Chinese Hackers Exploit Routers for Hidden Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark