Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Critical Vulnerabilities in Cisco and Kentico

CISA Highlights Critical Vulnerabilities in Cisco and Kentico

Posted on April 21, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog, incorporating eight additional flaws. Among these, three have not been previously identified as exploited, drawing attention from cybersecurity experts.

Cisco Catalyst SD-WAN Vulnerability

One of the prominent vulnerabilities is identified as CVE-2026-20133, a high-severity flaw in Cisco Catalyst SD-WAN Manager. Initially addressed in February, this bug could potentially allow unauthorized access to the system’s API, exposing sensitive information.

This particular flaw, along with CVE-2026-20122 and CVE-2026-20128, both related to SD-WAN vulnerabilities, was acknowledged by Cisco in March. CISA has now officially added these to the KEV list, emphasizing the need for immediate attention from organizations utilizing these systems.

Exploited Flaws in Kentico and Zimbra

CISA has also warned about two significant defects identified last year in Kentico Xperience and Zimbra Collaboration Suite. These vulnerabilities could lead to remote code execution, posing severe threats to affected systems.

The Kentico issue, categorized as CVE-2025-2749, involves path traversal and arbitrary file upload vulnerabilities, which could facilitate unauthorized content execution on servers. Despite requiring authentication, the potential for exploitation remains high, especially when combined with other known issues.

The Zimbra vulnerability, labeled CVE-2025-48700, is a cross-site scripting (XSS) flaw within the Zimbra Classic UI. This can be exploited by crafting specific messages that trigger JavaScript execution within a user’s session, potentially compromising data integrity.

Additional Vulnerabilities in Focus

In addition to the aforementioned issues, CISA has added three more vulnerabilities to its KEV catalog. These include CVE-2025-32975 in Quest KACE, noted for potential exploitation, CVE-2024-27199 in JetBrains TeamCity, exploited over a prolonged period, and CVE-2023-27351 in PaperCut, which has been a concern since early 2023.

CISA is urging federal agencies to prioritize patching the Cisco and Zimbra vulnerabilities by April 23, with the other vulnerabilities requiring attention by May 4. This proactive approach is crucial to safeguarding sensitive information and maintaining cybersecurity resilience.

Related articles explore similar vulnerabilities, including flaws in discontinued TP-Link routers and recent Apache ActiveMQ exploits, highlighting the evolving landscape of cybersecurity threats.

Security Week News Tags:CISA, Cisco, Cybersecurity, Exploits, information disclosure, Kentico, Patching, RCE, Security, Technology, Vulnerabilities, Zimbra

Post navigation

Previous Post: Understanding Identity-Based Cyber Attacks and Defense
Next Post: Hackers Exploit FortiGate VPN with Nightmare-Eclipse Tools

Related Posts

Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Security Week News
US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than  Billion in Bitcoin US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than $14 Billion in Bitcoin Security Week News
Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Security Week News
Red Access Raises  Million for Agentless Security Platform Red Access Raises $17 Million for Agentless Security Platform Security Week News
Broadcom Wi-Fi Chipset Flaw Allows Hackers to Disrupt Networks Broadcom Wi-Fi Chipset Flaw Allows Hackers to Disrupt Networks Security Week News
CrowdStrike to Buy Identity Security Firm SGNL for 0 Million in Cash CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark