Post
CRITICAL ⚡ MUST-KNOW

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog

· vulnerability · cve · privilege-escalation

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation: CVE-2025-67038 (Lantronix EDS5000 code injection), and three Ubiquiti UniFi OS flaws — CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), and CVE-2026-34910 (improper input validation). Federal agencies must remediate under Binding Operational Directive 26-04. Organizations running Lantronix EDS5000 or Ubiquiti UniFi OS should prioritize patching given confirmed in-the-wild exploitation.