The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities in Fortinet's FortiOS/FortiProxy and GitHub Action to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities, which are critical in nature, have drawn attention due to their potential exploitation. Additionally, a critical remote code execution vulnerability (CVE-2025-23120) was discovered in Veeam Backup & Replication, rated at 9.9 on the CVSS scale. Veeam has since released a patch to address this flaw. CISA also flagged a vulnerability in NAKIVO Backup & Replication that is actively being exploited, with details indicating that it could allow unauthorized access to sensitive data. Furthermore, vulnerabilities in Cisco's Smart Licensing Utility have been identified, with hackers actively exploiting them. The vulnerabilities in question are rated at 9.8 and pose serious risks, including access to admin credentials and APIs. Organizations are urged to update their systems promptly to mitigate these risks.
Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility: https://t.co/aGRFIrMXef by The Hacker News #infosec #cybersecurity #technology #news
The @CISAgov added a high-severity bug in GitHub Action tj-actions/changed files to its Known Exploited Vulnerabilities (KEV) catalog. #cybersecurity #infosec #ITsecurity https://t.co/p2Lumuiy87
🔥 Hardcoded admin logins. Leaky debug logs. Cisco Smart Licensing Utility is under fire. Hackers are actively exploiting CVE-2024-20439 & CVE-2024-20440—both rated 9.8. Access to admin creds & APIs is on the line. See the full story 👉 https://t.co/MPIrj800Gr