Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogcybersecurity-regulationinternet-facing-service-vulnerability

CISA Adds Four Actively Exploited Vulnerabilities to the KEV Catalog

Updated 3mo agoFirst seen Jan 23, 20267 sources

CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2025-31125 (Vite/Vitejs improper access control), CVE-2025-34026 (Versa Concerto improper authentication), CVE-2025-54313 (eslint-config-prettier embedded malicious code), and CVE-2025-68645 (Synacor Zimbra Collaboration Suite PHP remote file inclusion). Under Binding Operational Directive (BOD) 22-01, U.S. Federal Civilian Executive Branch agencies must remediate KEV-listed issues by CISA’s specified due dates; CISA also urged all organizations to prioritize patching these KEV entries as part of routine vulnerability management.

Reporting on the update highlighted technical risk details for several of the newly listed items, including an authentication bypass in Versa Concerto (reported as affecting versions 12.1.2 through 12.2.0) tied to a Traefik reverse-proxy misconfiguration that could expose administrative endpoints (including an internal Actuator endpoint with access to heap dumps and trace logs). It also described the supply-chain impact of the eslint-config-prettier malicious code issue, where installing affected versions can execute an install.js that launches Windows malware, and noted the Zimbra webmail flaw enabling unauthenticated file inclusion from the web root in affected 10.0/10.1 versions. Separately, CISA also published an ICS advisory for EVMAPA EV-charging infrastructure vulnerabilities, but that advisory is not part of the KEV-additions event.

Share:
CISA Adds Four Actively Exploited Vulnerabilities to the KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 12, 20264mo ago

CISA sets February 12 deadline for federal remediation

Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate or mitigate the four newly listed KEV vulnerabilities, or discontinue use of affected products, by February 12, 2026. Private-sector organizations were also urged to patch immediately.

Jan 22, 20265mo ago

CISA adds four actively exploited flaws to KEV catalog

CISA added CVE-2025-31125 in Vite, CVE-2025-34026 in Versa Concerto, CVE-2025-54313 in eslint-config-prettier, and CVE-2025-68645 in Synacor Zimbra Collaboration Suite to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The agency said the vulnerabilities pose significant risk and urged organizations to prioritize remediation.

Jan 14, 20265mo ago

CrowdSec observes exploitation attempts against Zimbra flaw

CrowdSec reported exploitation attempts targeting Synacor Zimbra Collaboration Suite vulnerability CVE-2025-68645 beginning on January 14, 2026. The flaw affects the Webmail Classic UI and can allow unauthenticated file inclusion from the WebRoot directory.

Jul 1, 20251y ago

npm supply-chain attack compromises eslint-config-prettier

A July 2025 npm supply-chain attack affected eslint-config-prettier and six other packages after maintainers were phished with credential-harvesting links. The compromise introduced embedded malicious code later tracked as CVE-2025-54313.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Affected products
5 linked
Zimbra Collaboration SuiteZimbra Collaboration SuiteZimbra Collaboration SuiteConcerto Sd-Wan Orchestration PlatformZimbra Collaboration Suite (Zcs)
Organizations
7 linked
ZimbraVersa-NetworksSecurity AffairsProjectdiscoveryBleepingComputerCrowdSecTines
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Adds Four Actively Exploited Vulnerabilities to the KEV Catalog | Mallory