CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog

CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog

The US CISA has expanded its KEV catalog to include vulnerabilities in XWiki and VMware, both actively exploited in the wild. These flaws pose significant risks, allowing remote code execution and privilege escalation, with threat actors already targeting them. #XWikiCVEs #VMwareThreats

Keypoints

  • The XWiki vulnerability (CVE-2025-24893) allows remote code execution through search parameter sanitization flaws.
  • Proof-of-concept exploits for XWiki first appeared about half a year ago, with active exploitation noted since March.
  • Threat actors are exploiting the XWiki flaw to deploy cryptocurrency miners in targeted systems.
  • The VMware privilege escalation flaw (CVE-2025-41244) enables attackers to gain root access on vulnerable VMs with VMware Tools.
  • Broadcom has issued patches for VMware, but active exploitation, particularly by Chinese threat actors, has been confirmed.

Read More: https://www.securityweek.com/cisa-adds-exploited-xwiki-vmware-flaws-to-kev-catalog/