• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    MS-ISAC

    MS-ISAC Flags High-Risk Security Flaws in Fortinet Products

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

    Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

    New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

    New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

    DNS Attack

    What Is a DNS Attack? Understanding the Risks and Threats

    Endesa Data Breach

    Spanish Energy Giant Endesa Notifies Customers of Data Breach Impacting Energía XXI

    Credit: Franz Bachinger/Pixabay

    Attackers Targeting LLMs in Widespread Campaign

    TCE-Exclusive-interview-with-Dr-Amit-Chaubey

    Inside the 2026 Business Blast Radius: Dr. Amit Chaubey on Why Cyber Disruption Is Now a Sovereign Risk

    Internet Blackout, Iran, Trump, Civil Unrest, Internet Shutdown

    84 Hrs and Counting as Internet Blackout in Iran Continues Amid Nationwide Unrest

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    FBI Seizes E-Note Crypto Exchange

    FBI Seizes E-Note Crypto Exchange Linked to Ransomware Money Laundering

    DPDP Act

    8 Ways the DPDP Act Will Change How Indian Companies Handle Data in 2026 

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

    Third-Party Risk Management in Healthcare

    Why Healthcare CISOs Must Prioritize Third-Party Risk Management

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    MS-ISAC

    MS-ISAC Flags High-Risk Security Flaws in Fortinet Products

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

    Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

    New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

    New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

    DNS Attack

    What Is a DNS Attack? Understanding the Risks and Threats

    Endesa Data Breach

    Spanish Energy Giant Endesa Notifies Customers of Data Breach Impacting Energía XXI

    Credit: Franz Bachinger/Pixabay

    Attackers Targeting LLMs in Widespread Campaign

    TCE-Exclusive-interview-with-Dr-Amit-Chaubey

    Inside the 2026 Business Blast Radius: Dr. Amit Chaubey on Why Cyber Disruption Is Now a Sovereign Risk

    Internet Blackout, Iran, Trump, Civil Unrest, Internet Shutdown

    84 Hrs and Counting as Internet Blackout in Iran Continues Amid Nationwide Unrest

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    FBI Seizes E-Note Crypto Exchange

    FBI Seizes E-Note Crypto Exchange Linked to Ransomware Money Laundering

    DPDP Act

    8 Ways the DPDP Act Will Change How Indian Companies Handle Data in 2026 

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

    Third-Party Risk Management in Healthcare

    Why Healthcare CISOs Must Prioritize Third-Party Risk Management

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog

Ashish Khaitan by Ashish Khaitan
September 30, 2025
in Firewall Daily, Cyber News, Vulnerabilities
0
CVE-2021-21311
608
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding five new security flaws that are confirmed to be under active exploitation.  

The newly listed vulnerabilities, spanning critical systems such as databases, network operating systems, email gateways, and file transfer platforms, include CVE-2021-21311, CVE-2025-20352, CVE-2025-10035, CVE-2025-59689, and CVE-2025-32463. 

Detailed Breakdown of the Five Vulnerabilities 

CVE-2021-21311 – Adminer SSRF Vulnerability 

First disclosed in early 2021, this Server-Side Request Forgery (SSRF) vulnerability affects Adminer versions from 4.0.0 to just before 4.7.9. Adminer, a lightweight PHP-based database management tool, is vulnerable to manipulation of URL parameters that can result in unauthorized internal resource access.  

With a CVSS score of 7.2, this issue is categorized as high severity. Attackers exploiting this flaw could use Adminer to proxy requests to otherwise inaccessible systems, potentially enabling lateral movement or reconnaissance within internal networks. 

CVE-2025-20352 – Cisco IOS / IOS XE Stack-Based Buffer Overflow 

This newly disclosed vulnerability in Cisco’s IOS and IOS XE operating systems affects multiple versions supporting the Simple Network Management Protocol (SNMP). Identified as a stack-based buffer overflow, the flaw can be triggered by an attacker sending specially crafted SNMP packets.

Depending on the attacker’s privileges, the result can range from a simple denial of service to full remote code execution as the root user. With a CVSS score of 7.7, this vulnerability poses a substantial threat to enterprise and government network infrastructure. 

report-ad-banner

CVE-2025-10035 – GoAnywhere MFT Deserialization Vulnerability 

Affecting GoAnywhere MFT versions 0 through 7.8.3, this critical flaw (CVSS 10.0) lies in the application’s handling of serialized data in its License Servlet. Malicious actors can exploit this deserialization weakness to execute arbitrary commands, making it a prime target for attackers seeking to compromise sensitive file transfer systems. Fortra, the vendor, urges users to apply patches immediately and reinforce input validation mechanisms. 

CVE-2025-59689 – Libraesva Email Gateway Command Injection 

This vulnerability, found in multiple versions of Libraesva’s Email Security Gateway (ESG), allows attackers to inject and execute shell commands via improperly sanitized email attachments.  

While rated medium severity (CVSS 6.1), its presence in a security appliance that handles inbound and outbound email traffic makes it a valuable entry point for attackers. Successful exploitation can result in system compromise and potential internal access. 

CVE-2025-32463 – Sudo Privilege Escalation via Untrusted Control Sphere 

Sudo, a core utility in Unix and Linux systems, is vulnerable in versions from 1.9.14 to 1.9.17p1. The vulnerability stems from unsafe handling of external control functionality, particularly involving /etc/nsswitch.conf in chroot environments. With a critical CVSS rating of 9.3, exploitation could grant an unprivileged user root-level access. 

Why Inclusion in the KEV Catalog Matters 

The addition of these vulnerabilities, CVE-2021-21311, CVE-2025-20352, CVE-2025-10035, CVE-2025-59689, and CVE-2025-32463, signals that each is confirmed to be actively exploited.  

CISA’s KEV list is not theoretical; it reflects real-world threats, often leveraged by threat actors in advanced persistent campaigns or ransomware operations. The catalog acts as a call to action, urging organizations to remediate vulnerabilities that attackers are known to be using right now. 

Affected Products and Versions 

  • Cisco IOS/IOS XE – Over 349 IOS XE versions and 21 Catalyst SD-WAN releases are affected by CVE-2025-20352. 
  • Fortra GoAnywhere MFT – All versions up to 7.8.3 are impacted by CVE-2025-10035. 
  • Libraesva ESG – Multiple branches from 4.5 to 5.5 are vulnerable to CVE-2025-59689. 
  • Sudo – Versions from 1.9.14 to before 1.9.17p1 are affected by CVE-2025-32463. 
  • Adminer – Versions up to 4.7.8 require upgrading to at least 4.7.9 to address CVE-2021-21311. 

Mitigation and Response Strategies 

CISA advises organizations to: 

  • Apply available patches as soon as vendor updates are released. 
  • Implement compensating controls where patching is not immediately feasible, such as access restrictions, input validation, and segmentation. 
  • Enhance monitoring and detection for signs of exploitation attempts, such as suspicious SNMP traffic, unusual command execution, or unexpected Adminer behavior. 
  • Conduct threat hunting activities focusing on privilege escalation attempts or anomalous file transfer activity. 

Share this:

  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • More
  • Click to email a link to a friend (Opens in new window) Email
  • Click to share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CISACVE-2021-21311CVE-2025-10035CVE-2025-20352The Cyber ExpressThe Cyber Express News
Previous Post

WiFi Sniffer Leads to Russian Spying Charges for Dutch Teens

Next Post

Bitcoin Queen Convicted in U.K.’s Largest-Ever Crypto Seizure Tied to China Fraud

Next Post
Zhimin Qian, Bitcoin Queen

Bitcoin Queen Convicted in U.K.’s Largest-Ever Crypto Seizure Tied to China Fraud

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

MS-ISAC
Firewall Daily

MS-ISAC Flags High-Risk Security Flaws in Fortinet Products

January 14, 2026
Nicole Ozer appointment
Appointments

Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

January 14, 2026
Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws
Cyber News

Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

January 13, 2026
New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities
Cyber News

New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

January 13, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information