AI Stories on SHORT INFO are generated & curated with AI
unverified 05 Jul, 09:09

CISA adds actively exploited Splunk and Cisco flaws to its Known Exploited Vulnerabilities catalog, underlining that identity and enterprise apps remain the ransomware entry point

CISA has added actively exploited flaws in Splunk Enterprise (CVE-2026-20253, missing authentication) and Cisco $CSCO Unified Communications Manager (CVE-2026-20230, SSRF) to its Known Exploited Vulnerabilities catalog, with binding fix deadlines for federal agencies. Source: CIS

Two more enterprise systems have moved from theoretical risk to confirmed target. CISA has added a pair of actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. One is a missing authentication for a critical function flaw in Splunk Enterprise, tracked as CVE-2026-20253. The other is a server side request forgery vulnerability in Cisco $CSCO Unified Communications Manager, tracked as CVE-2026-20230. Why the catalog matters: an entry is not a prediction of risk, it is evidence of exploitation already seen in the wild. For US federal civilian agencies, listing triggers a binding deadline to patch. For private operators, it is the closest thing to a public confirmation that a bug is being used against real targets right now. The throughline of 2026 has not changed. Ransomware and intrusion crews keep returning to the same categories: identity platforms, monitoring and logging stacks, and enterprise communication systems. Those are the tools that sit deep inside a network and see everything, which is exactly why they are worth breaking into. Source: Cybersecurity and Infrastructure Security Agency.

Published on
ThreadsFacebookBlueskyX