View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

CISA Adds Six Actively Exploited Flaws to KEV Catalog

🔓 CVEs & KEV

  • CVE-2026-77991 — CVSS 9.4 — Joomla Extension - joomlaeventmanager.net - Privileged remote code execution ...

  • CVE-2026-59270 — CVSS 9.4 — Spring Security UnboundID LDAP Server Critical Admin Credential Exposure (CVE-2026-59270)

  • CVE-2026-76148 — CVSS 8.4 — CorvusSKK contains a code injection vulnerability, which may lead to arbitrar...

  • CVE-2026-29988 — CVSS 8.3 — A cleartext transmission of sensitive information vulnerability in the NFC in...

  • CVE-2026-58091 — CVSS 7.8 — Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctlThe implementation of...

  • CVE-2026-58090 — CVSS 7.8 — Use-after-free in unix SOCK_STREAM message handlingThe SOCK_STREAM receive pa...

  • CVE-2026-58089 — CVSS 7.8 — hwpmc fails to detach PMCs during exec credential transitionsWhen a process c...

📋 ADVISORIES

  • 📄 Source for CISA Adds Six Actively Exploited Flaws to KEV Catalogcisa.gov

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check