Site icon VMVirtualMachine.com

Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

By Ionut Arghire
Publication Date: 2026-04-21 11:19:00

The US cybersecurity agency CISA on Monday expanded its Known Exploited Vulnerabilities (KEV) catalog with eight more flaws, including three that have not previously been flagged as exploited.

The most recent of these is CVE-2026-20133, a high-severity information disclosure bug in Cisco Catalyst SD-WAN Manager that was patched in February.

Insufficient file system access restrictions could allow an attacker to access the API of an affected system and read information on the underlying operating system.

The CVE was disclosed in February alongside CVE-2026-20122 and CVE-2026-20128, two SD-WAN flaws that Cisco flagged as exploited in March. Now, CISA has added all three to the KEV list.

The agency also warned that two security defects disclosed last year in Kentico Xperience and Zimbra Collaboration Suite (ZCS), both leading to remote code execution (RCE), have been exploited in attacks.

Tracked as CVE-2025-2749, the Kentico bug is described as a path traversal and…

Exit mobile version