[Vulnerability Alert] CISA Adds 3 Known Exploited Vulnerabilities to KEV Catalog (2026/02/23-2026/03/01)
Subject Explanation: [Vulnerability Alert] CISA Adds 3 Known Exploited Vulnerabilities to KEV Catalog (2026/02/23-2026/03/01)
Content Description:
Forwarding Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) Security Alert TWCERTCC-200-202603-00000001
[CVE-2026-25108] Soliton Systems K.K FileZen OS Command Injection Vulnerability (CVSS v3.1: 8.8)
[Ransomware Exploitation: Unknown] Soliton Systems K.K FileZen contains an OS command injection vulnerability. This vulnerability can be triggered when a user logs into the affected product and sends a specially crafted HTTP request.
[Ransomware Exploitation: Unknown] A path traversal vulnerability exists in the Cisco SD-WAN CLI. Due to improper command access control within the application CLI, an authenticated local attacker could exploit this to escalate privileges. Upon successful exploitation, an attacker could execute arbitrary commands as the root user.
[Ransomware Exploitation: Unknown] Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) contain an authentication bypass vulnerability. This could allow an unauthenticated remote attacker to bypass authentication mechanisms and gain administrative privileges on the affected system.