Four new (from past years) vulnerabilities to be monitored after CISA flags them as exploited

 Four vulnerabilities were added by CISA, the American cybersecurity agency, to its catalog of vulnerabilities that are known to be exploited. The additions to the catalog made on July 7 2025 did not include any zero days (unknown to the product vendor) or recently discovered vulnerabilities. One was a vulnerability from 2014, another was from 2016 while two more were from 2019.

CVE-2014-3931 is an arbitrary-memory-write vulnerability in MRLG (Multi Router Looking Glass) which was fixed in version 5.5.0

CVE-2016-10033 is a critical arbitrary code execution vulnerability in PHPMailer before version 5.2.18. Latest version can be found here.

CVE-2019-5418 is a file-content exposure vulnerability in Action View with possible remote code execution (exploit available) in versions 5.2.2.1, 5.1.6.2, 5.0.7.2 and 4.2.11.1

CVE-2019-9621 is a Server Side Reuest Forgery vulnerability in Zimbra Collaboration Suite that was fixed in version 8.8.1 Patch 7 or 8.8.11 Patch 3

Comments

Popular posts from this blog

Microsoft warns of SharePoint exploitation, says enable AMSI to stay secure!

Citrix NetScaler ADC and Gateway has been exploited: Patch now!