Organizations Urged to Patch Actively Exploited Cisco, Kentico, and Zimbra Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog, adding eight new security flaws that are currently being leveraged in real-world attacks, prompting urgent warnings for organizations to apply patches.

Among the newly listed issues are three vulnerabilities affecting Cisco’s Catalyst SD-WAN Manager—CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133—which include risks such as privilege escalation, credential exposure, and sensitive information disclosure. These flaws could allow attackers to access system APIs, overwrite files, or extract confidential data from affected environments.

CISA also highlighted vulnerabilities in Kentico Xperience and Zimbra Collaboration Suite that have been actively exploited. The Kentico flaw (CVE-2025-2749) is a path traversal and arbitrary file upload issue that can enable remote code execution when exploited. Meanwhile, a Zimbra vulnerability (CVE-2025-48700) allows attackers to execute malicious scripts within user sessions, potentially leading to unauthorized access and data compromise.

In addition to these, other vulnerabilities added to the KEV catalog affect platforms such as JetBrains TeamCity, Quest KACE, and PaperCut, underscoring the wide range of enterprise systems currently at risk.

CISA has set strict remediation deadlines, urging federal agencies to patch Cisco and Zimbra-related vulnerabilities by April 23, while fixes for other issues must be applied by early May.

Security experts emphasize that vulnerabilities included in the KEV catalog are known to be actively exploited, making them high-priority risks. The update reflects a broader trend where attackers rapidly weaponize newly discovered flaws, reinforcing the need for organizations to adopt proactive patch management and continuously monitor their systems for potential threats.
- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch