Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Exploited Vulnerabilities in Key Software

CISA Highlights Exploited Vulnerabilities in Key Software

Posted on March 10, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new alert concerning vulnerabilities in prominent software systems, highlighting their active exploitation by cyber attackers. On Monday, CISA updated its Known Exploited Vulnerabilities (KEV) catalog to include three critical security flaws, emphasizing the urgency for organizations to address these weaknesses.

Critical Vulnerabilities Identified

The vulnerabilities added to the KEV catalog involve software from Omnissa Workspace One, SolarWinds, and Ivanti. Specifically, CVE-2021-22054 affects the Workspace One UEM, presenting a server-side request forgery (SSRF) issue that can be exploited to gain unauthorized access to sensitive data. Another significant flaw, CVE-2025-26399, impacts the SolarWinds Web Help Desk, allowing attackers to execute commands via deserialization of untrusted data. Furthermore, CVE-2026-1603 in Ivanti Endpoint Manager can lead to credential leakage due to an authentication bypass vulnerability.

Exploitation Evidence and Threat Response

Microsoft and Huntress have reported active exploitation of the SolarWinds vulnerability by threat actors, suspected to be the Warlock ransomware group. Additionally, the SSRF vulnerability in Workspace One was previously identified by GreyNoise as part of a broader exploit campaign. Currently, there is limited information on the active exploitation of the Ivanti vulnerability, and its security bulletin remains unupdated in this regard.

Federal Response and Security Measures

In response to these threats, CISA has directed Federal Civilian Executive Branch (FCEB) agencies to mitigate risks by applying necessary patches. Agencies are required to address the SolarWinds Web Help Desk vulnerability by March 12, 2026, and complete updates for the Workspace One and Ivanti vulnerabilities by March 23, 2026. These measures are critical to safeguarding federal systems from potential breaches.

CISA underscores the significance of these vulnerabilities as frequent targets for cyber attackers, posing elevated risks to federal operations. Organizations are encouraged to prioritize these updates to fortify their cybersecurity defenses against ongoing threats.

The Hacker News Tags:CISA, cyber threats, Cybersecurity, exploited vulnerabilities, federal security, Ivanti, security flaws, SolarWinds, Vulnerabilities, Workspace One

Post navigation

Previous Post: Malware Disguised as Teams and Zoom Apps Targets Enterprises
Next Post: Anthropic Challenges U.S. ‘Supply Chain Risk’ Designation

Related Posts

Discover Practical AI Tactics for GRC — Join the Free Expert Webinar Discover Practical AI Tactics for GRC — Join the Free Expert Webinar The Hacker News
High-Severity Vulnerability Patched in n8n Workflow Platform High-Severity Vulnerability Patched in n8n Workflow Platform The Hacker News
Critical Metro4Shell Vulnerability Exploited in React Native Critical Metro4Shell Vulnerability Exploited in React Native The Hacker News
Kimsuky Expands Cyber Arsenal with New Techniques Kimsuky Expands Cyber Arsenal with New Techniques The Hacker News
The Costly Confusion Behind Security Risks The Costly Confusion Behind Security Risks The Hacker News
Announcing Cybersecurity Stars Awards 2026 Announcing Cybersecurity Stars Awards 2026 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark