Vulnerabilità ed exploit

Cisco SD-WAN Flaw Joins KEV Without Vendor Confirmation

CISA’s latest KEV update says defenders cannot wait for vendor confirmation before treating a flaw as live attack surface. The unusual part is CVE-2026-20133: CISA added it to the exploited list even though Cisco has not yet flagged it, which suggests exploitation may be happening before the vendor has fully acknowledged it.

The batch covers eight flaws across Cisco Catalyst SD-WAN Manager, Kentico Xperience, Zimbra Collaboration Suite, PaperCut NG/MF, JetBrains TeamCity, and Quest KACE Systems Management Appliances. The Kentico issue, CVE-2025-2749, affects Xperience 13.0.178 and earlier and can let an attacker execute content on the server remotely; CISA also says the Zimbra, PaperCut, TeamCity, and KACE issues have been used in attacks.

For practitioners, the forward risk is not just the known exploited set. A KEV entry that arrives before the vendor’s exploitation notice is a warning that some activity may still be hidden, especially around Cisco SD-WAN where confirmed attacks already exist.

5 fonti · 21 apr

CVE-2026-20133

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 6.5 MEDIUM: a vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive… EPSS 32% (98º percentile).

Data di correzione federale CISA 23 apr

CVE-2025-32975

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84º percentile).

Data di correzione federale CISA 4 mag

CVE-2023-27351

NVD KEV

CVE-2024-27199

NVD KEV

Cronologia

Fonti

Riepilogo fornitore: Cisco

Part of the PlainSec briefing for 2026-04-21

Every edition of this story: Cisco SD-WAN Flaw Joins KEV Without Vendor Confirmation

Altro da oggi