patch&proof.
← The dispatch

vulnerability / Source brief

Five additions to CISA's exploited-vulnerability catalogue sharpened the patch queue

CISA added flaws affecting Adminer, Cisco IOS and IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and Sudo after finding evidence of acti…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Five additions to CISA’s exploited-vulnerability catalogue sharpened the patch queue.

What happened. CISA added flaws affecting Adminer, Cisco IOS and IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and Sudo after finding evidence of active exploitation.

Impact and confidence

The catalogue establishes exploitation, not how many organizations were compromised. Product presence and exposure still determine local urgency.

Defensive takeaway

Reconcile the five CVEs against an authoritative asset inventory. Treat absence of an asset match as an evidence result, not an assumption.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2025-09-29
Event date
2025-09-29
Site publication
Unpublished · local review
CISA Adds Five Known Exploited Vulnerabilities to Catalog
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval