CISA Warns: SysAid Flaws Under Active Attack Enable Remote File Access and SSRF

CISA Warns: SysAid Flaws Under Active Attack Enable Remote File Access and SSRF

The U.S. CISA has added two critical vulnerabilities in SysAid IT support software to its KEV catalog due to active exploitation evidence. These flaws could enable attackers to perform SSRF attacks and remote code execution, posing significant security risks. #SysAid #CISA #XXE #CVE20252775 #CVE20252776

Keypoints

  • Two high-severity vulnerabilities in SysAid software have been added to CISA’s KEV catalog.
  • The flaws, CVE-2025-2775 and CVE-2025-2776, both have a CVSS score of 9.3.
  • They involve improper restrictions of XML external entities, leading to administrator account takeover.
  • The vulnerabilities were disclosed by watchTowr Labs researchers in May and addressed in March 2025.
  • FCEB agencies must apply security patches by August 12, 2025, to prevent exploitation.

Read More: https://thehackernews.com/2025/07/cisa-warns-sysaid-flaws-under-active.html