惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
U
Unit 42
IT之家
IT之家
Y
Y Combinator Blog
T
Tailwind CSS Blog
B
Blog
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
I
InfoQ
J
Java Code Geeks
F
Fortinet All Blogs
T
The Blog of Author Tim Ferriss
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
H
Hackread – Cybersecurity News, Data Breaches, AI and More
人人都是产品经理
人人都是产品经理
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
GbyAI
GbyAI
博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
L
LangChain Blog

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
U.S. CISA adds Microsoft and Adobe flaws to its Known Exp...
Pierluigi Pa · 2026-05-22 · via Security Affairs

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability
  • CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability
  • CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
  • CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability
  • CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability
  • CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability
  • CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability

CVE-2008-4250 (CVSS v3.1 score of 9.8) is a critical remote code execution flaw in the Microsoft Windows Server service, associated with the MS08-067 vulnerability. It affects older versions of Windows, including Windows XP, Server 2003, Vista, and Server 2008. Attackers can exploit it remotely by sending specially crafted RPC requests that trigger a buffer overflow during path canonicalization, allowing arbitrary code execution without authentication.

The second flaw added to the catalog (tracked as CVE-2009-1537, CVSS v2 score of 9.3) is a critical vulnerability in Microsoft DirectX caused by a NULL byte overwrite issue. It affects multiple Windows versions and can allow remote code execution if a user opens a specially crafted QuickTime media file. Successful exploitation could let attackers run arbitrary code with the privileges of the logged-in user.

The third flaw added to the catalog (tracked as CVE-2009-3459, CVSS v2 score of 9.3) is a critical heap-based buffer overflow vulnerability in Adobe Acrobat and Adobe Reader. Attackers can exploit the flaw using a specially crafted PDF file, potentially leading to arbitrary code execution on vulnerable systems when the document is opened.

The fourth flaw added to the catalog (tracked as CVE-2010-0249, CVSS v2 score of 9.3) is a critical use-after-free vulnerability in Microsoft Internet Explorer. The flaw can be triggered through malicious web content, allowing remote attackers to execute arbitrary code in the context of the current user after visiting a crafted website.

The fifth flaw added to the catalog (tracked as CVE-2010-0806, CVSS v2 score of 9.3) is another critical use-after-free vulnerability in Microsoft Internet Explorer. It affects older IE versions and allows attackers to gain remote code execution by convincing users to visit a malicious webpage containing specially crafted HTML and scripting content. The APT group GREF exploited the flaw as a zero-day in targeted attacks.

The sixth flaw added to the catalog (tracked as CVE-2026-41091, CVSS v3.1 score of 7.8) is a Microsoft Defender elevation of privilege vulnerability. Successful exploitation could allow a local attacker to gain higher privileges on the affected system, potentially enabling further compromise or lateral movement within a network.

The seventh flaw added to the catalog (tracked as CVE-2026-45498, CVSS v3.1 score of 6.5) is a denial-of-service vulnerability in Microsoft Defender. An attacker could exploit the flaw to cause security services to become unavailable or unresponsive, impacting the protection capabilities of affected Windows systems.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by June 3, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)