{"id":11086,"date":"2026-01-23T22:23:42","date_gmt":"2026-01-23T22:23:42","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=11086"},"modified":"2026-01-23T22:23:42","modified_gmt":"2026-01-23T22:23:42","slug":"cisa-updates-kev-catalog-with-4-actively-exploited-software-program-vulnerabilities","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=11086","title":{"rendered":"CISA Updates KEV Catalog with 4 Actively Exploited Software program Vulnerabilities"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jan 23, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Software program Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhhfzkSnP6sxVF7yvf0PInrv1BOfApvDuKFwOcutnIngSLkUJQltRqdFGjdFWnYJ8H4zHyADNqiELIsFuGEc0X9DxSwjbdy118pus7cNpytqoSyrrfuf7ECvPIiLG5NxEezMZe5wjVVzTE7OhuMee-o8XDCuOo2c9w337yxPGeMkeAleuGKSzqFTHivrCjY\/s1600-e365\/cisa.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhhfzkSnP6sxVF7yvf0PInrv1BOfApvDuKFwOcutnIngSLkUJQltRqdFGjdFWnYJ8H4zHyADNqiELIsFuGEc0X9DxSwjbdy118pus7cNpytqoSyrrfuf7ECvPIiLG5NxEezMZe5wjVVzTE7OhuMee-o8XDCuOo2c9w337yxPGeMkeAleuGKSzqFTHivrCjY\/s1600-e365\/cisa.jpg\" alt=\"\" border=\"0\" data-original-height=\"380\" data-original-width=\"728\"\/><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Thursday <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/01\/22\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" rel=\"noopener\" target=\"_blank\">added<\/a> 4 safety flaws to its Identified Exploited Vulnerabilities (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" rel=\"noopener\" target=\"_blank\">KEV<\/a>) catalog, citing proof of lively exploitation within the wild.<\/p>\n<p>The record of vulnerabilities is as follows &#8211;<\/p>\n<ul>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-68645\" rel=\"noopener\" target=\"_blank\">CVE-2025-68645<\/a><\/strong> (CVSS rating: 8.8) &#8211; A <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cwe.mitre.org\/data\/definitions\/98.html\" rel=\"noopener\" target=\"_blank\">PHP distant file inclusion<\/a> vulnerability in Synacor Zimbra Collaboration Suite (ZCS) that might permit a distant attacker to craft requests to the &#8220;\/h\/relaxation&#8221; endpoint and permit inclusion of arbitrary information from the WebRoot listing with none authentication (Fastened in November 2025 with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/wiki.zimbra.com\/wiki\/Security_Center\" rel=\"noopener\" target=\"_blank\">model 10.1.13<\/a>)<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-34026\" rel=\"noopener\" target=\"_blank\">CVE-2025-34026<\/a><\/strong> (CVSS rating: 9.2) &#8211; An <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/projectdiscovery.io\/blog\/versa-concerto-authentication-bypass-rce\" rel=\"noopener\" target=\"_blank\">authentication bypass<\/a> within the Versa Concerto SD-WAN orchestration platform that might permit an attacker to entry administrative endpoints (Fastened in April 2025 with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/05\/unpatched-versa-concerto-flaws-let.html\" rel=\"noopener\" target=\"_blank\">model 12.2.1 GA<\/a>)<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-31125\" rel=\"noopener\" target=\"_blank\">CVE-2025-31125<\/a><\/strong> (CVSS rating: 5.3) &#8211; An improper entry management vulnerability in Vite Vitejs that might permit contents of arbitrary information to be returned to the browser utilizing ?inline&amp;import or ?uncooked?import (Fastened in March 2025 with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/vitejs\/vite\/security\/advisories\/GHSA-4r4m-qw57-chr8\" rel=\"noopener\" target=\"_blank\">variations 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11<\/a>)<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-54313\" rel=\"noopener\" target=\"_blank\">CVE-2025-54313<\/a><\/strong> (CVSS rating: 7.5) &#8211; An embedded malicious code vulnerability in eslint-config-prettier that might permit for execution of a malicious DLL dubbed Scavenger Loader that is designed to ship an info stealer<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/attack-surface-insight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgj01_-EPEkxaROaED9e8h2OIIeT0oXXmcnWEAb3xbOAumwdFU9z8fpwY4vjL11Reywiz9PTesXqQ86D2Eb6FQI46Rcq3mfmaqzr4RxV8S18OBZ7YrmcPIm3T-5ki1ME8gNTIwhKiysr2545hOD7b_O4k9GLx5L4XWdPyaRHJggufYNeAFej_TqWhlmNWxL\/s728-e100\/Sprocket-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It is price noting that CVE-2025-54313 refers to a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/07\/malware-injected-into-6-npm-packages.html\" rel=\"noopener\" target=\"_blank\">provide chain assault<\/a> focusing on eslint-config-prettier and 6 different npm packages, eslint-plugin-prettier, synckit, @pkgr\/core, napi-postinstall, got-fetch, and is, that got here to gentle in July 2025.<\/p>\n<p>The phishing marketing campaign focused the bundle maintainers with bogus hyperlinks that harvested their credentials underneath the pretext of verifying their e mail handle as a part of common account upkeep, permitting the menace actors to publish trojanized variations.<\/p>\n<p>In keeping with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/app.crowdsec.net\/cti\/cve-explorer\/CVE-2025-68645\" rel=\"noopener\" target=\"_blank\">CrowdSec<\/a>, exploitation efforts focusing on CVE-2025-68645 have been ongoing since January 14, 2026. There are presently no particulars on how the opposite vulnerabilities are being exploited within the wild.<\/p>\n<p>Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Govt Department (FCEB) businesses are required to use the mandatory fixes by February 12, 2026, to safe their networks towards lively threats.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jan 23, 2026Vulnerability \/ Software program Safety The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Thursday added 4 safety flaws to its Identified Exploited Vulnerabilities (KEV) catalog, citing proof of lively exploitation within the wild. The record of vulnerabilities is as follows &#8211; CVE-2025-68645 (CVSS rating: 8.8) &#8211; A PHP distant file inclusion [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":11088,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1993,7526,1359,1994,4988,802,614,2721],"class_list":["post-11086","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-actively","tag-catalog","tag-cisa","tag-exploited","tag-kev","tag-software","tag-updates","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11086"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11086\/revisions"}],"predecessor-version":[{"id":11087,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11086\/revisions\/11087"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/11088"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-12 05:15:20 UTC -->