Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Updates KEV Catalog with 4 Critical Vulnerabilities Following Ongoing Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalogue by including four critical security vulnerabilities affecting widely-used enterprise software and development tools.

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalogue by including four critical security vulnerabilities affecting widely-used enterprise software and development tools.

These vulnerabilities were added on Mon, Jan 22, 2026, with a compliance deadline set for Mon, Feb 12, 2026. Federal agencies and critical infrastructure operators are required to implement the necessary patches or mitigations by this date.

The vulnerabilities pose various threats, ranging from supply chain compromises to infrastructure orchestration platforms. Organizations using the impacted products should prioritize addressing these vulnerabilities to prevent unauthorized access, data exfiltration, and lateral movement within their networks.

Affected Products and Vulnerability Details

Vendor Product CVE ID Vulnerability Type Severity

Prettier eslint-config-prettier CVE-2025-54313 Embedded Malicious Code (CWE-506) Critical

These vulnerabilities were added on Mon, Jan 22, 2026, with a compliance deadline set for Mon, Feb 12, 2026.
Grace Bennett · Thehackingpost

Vite Vitejs CVE-2025-31125 Improper Access Control (CWE-200, CWE-284) Critical

Versa Concerto SD-WAN CVE-2025-34026 Improper Authentication (CWE-288) Critical

Synacor Zimbra Collaboration Suite CVE-2025-68645 PHP Remote File Inclusion (CWE-98) Critical

Organizations must promptly audit systems using the affected software versions. For Prettier eslint-config-prettier and Vite Vitejs, developers should assess package dependencies, revert to updated versions, and review CI/CD logs for any irregular activities.

Advertisement

Versa Concerto deployments require credential rotation and network segmentation analysis, especially for systems exposing administrative interfaces. Zimbra administrators are advised to apply vendor-provided security updates and implement web application firewall rules to limit access to vulnerable endpoints.

CISA emphasizes adherence to Binding Operational Directive 22-01 for federal agencies utilizing cloud services. Organizations should synchronize patch deployment across development, staging, and production environments and monitor for exploitation indicators such as unexpected process execution, unauthorized file access, and abnormal authentication patterns.

The expansion of the KEV Catalog highlights the intersection of development tool compromise and infrastructure vulnerabilities, necessitating coordinated incident response and proactive patch management across the software supply chain.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories