CISA Orders Emergency Patches for SolarWinds, Ivanti, Workspace One
CISA added three vulnerabilities affecting SolarWinds Web Help Desk, Ivanti Endpoint Manager, and Workspace One UEM to its Known Exploited Vulnerabilities catalog. Federal civilian agencies must patch the SolarWinds flaw within one week and the Ivanti and Workspace One flaws within two weeks after evidence of active exploitation.
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).
CISA federal remediation date Feb 27 · date passed
CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96th percentile), up from 0.4%.
CISA federal remediation date Feb 27 · date passed
CISA warns of actively exploited Ivanti EPM and Cisco SD-WAN flaws
Patched vulnerabilities in Ivanti Endpoint Manager and Cisco Catalyst SD-WAN are under attack, according to the US security agency, which added reporting requirements to its previous Cisco directive.
CISA shortens patch deadline for critical Ivanti, SolarWinds bugs
The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies until Thursday to patch CVE-2025-26399 — a critical vulnerability impacting the popular SolarWinds Web Help Desk.