Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Exploited Vulnerabilities in Key Software

CISA Highlights Exploited Vulnerabilities in Key Software

Posted on March 10, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new alert concerning vulnerabilities in prominent software systems, highlighting their active exploitation by cyber attackers. On Monday, CISA updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical security flaws, emphasizing the urgency for organizations to address these weaknesses.

Critical Vulnerabilities Identified

The vulnerabilities added to the KEV catalog involve software from Omnissa Workspace One, SolarWinds, and Ivanti. Specifically, CVE-2021-22054 affects the Workspace One UEM, presenting a server-side request forgery (SSRF) issue that can be exploited to gain unauthorized access to sensitive data. Another significant flaw, CVE-2025-26399, impacts the SolarWinds Web Help Desk, allowing attackers to execute commands via deserialization of untrusted data. Furthermore, CVE-2026-1603 in Ivanti Endpoint Manager can lead to credential leakage due to an authentication bypass vulnerability.

Exploitation Evidence and Threat Response

Microsoft and Huntress have reported active exploitation of the SolarWinds vulnerability by threat actors, suspected to be the Warlock ransomware group. Additionally, the SSRF vulnerability in Workspace One was previously identified by GreyNoise as part of a broader exploit campaign. Currently, there is limited information on the active exploitation of the Ivanti vulnerability, and its security bulletin remains unupdated in this regard.

Federal Response and Security Measures

In response to these threats, CISA has directed Federal Civilian Executive Branch (FCEB) agencies to mitigate risks by applying necessary patches. Agencies are required to address the SolarWinds Web Help Desk vulnerability by March 12, 2026, and complete updates for the Workspace One and Ivanti vulnerabilities by March 23, 2026. These measures are critical to safeguarding federal systems from potential breaches.

CISA underscores the significance of these vulnerabilities as frequent targets for cyber attackers, posing elevated risks to federal operations. Organizations are encouraged to prioritize these updates to fortify their cybersecurity defenses against ongoing threats.

The Hacker News Tags:CISA, cyber threats, Cybersecurity, exploited vulnerabilities, federal security, Ivanti, security flaws, SolarWinds, Vulnerabilities, Workspace One

Post navigation

Previous Post: Malware Disguised as Teams and Zoom Apps Targets Enterprises
Next Post: Anthropic Challenges U.S. ‘Supply Chain Risk’ Designation

Related Posts

Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories The Hacker News
Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host The Hacker News
Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools The Hacker News
Kimsuky Expands Cyber Arsenal with New Techniques Kimsuky Expands Cyber Arsenal with New Techniques The Hacker News
Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub The Hacker News
Vendors Address Critical Security Vulnerabilities in Software Vendors Address Critical Security Vulnerabilities in Software The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenSSL Addresses Critical Vulnerability with AI Assistance
  • Microsoft Addresses GitHub Security Breach Amid Ongoing Probe
  • Microsoft Entra Logs Expose Risky Agent Activities
  • Claude Mythos Revolutionizes Exploit Creation with AI
  • FROST Attack Exploits SSD Timing to Track Website Visits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenSSL Addresses Critical Vulnerability with AI Assistance
  • Microsoft Addresses GitHub Security Breach Amid Ongoing Probe
  • Microsoft Entra Logs Expose Risky Agent Activities
  • Claude Mythos Revolutionizes Exploit Creation with AI
  • FROST Attack Exploits SSD Timing to Track Website Visits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark