CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Federal agencies are required under BOD 26-04 to prioritize rapid remediation of vulnerabilities in the KEV Catalog, particularly those on publicly exposed assets, though CISA encourages all organizations to adopt this risk-based vulnerability management approach. Code injection vulnerabilities represent a frequent attack vector for threat actors and pose significant risks to enterprise environments.
Attackers can exploit a networking vulnerability in NVIDIA's OpenClaw tool to gain unauthenticated access to the local model server via the Ollama API, enabling persistent corruption of AI agents. The flaw allows threat actors to conduct LLM poisoning attacks by manipulating the underlying model through this unprotected interface. This attack vector poses significant risks to organizations deploying NVIDIA's AI tools in production environments.
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981), both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin are being actively exploited in the wild. Notably, the paid editions of the plugin were never listed as vulnerable in any CVE database despite being affected, and affected organizations require manual patching to remediate these flaws.
Researchers have identified a chained SharePoint sequence vulnerability that enables authentication bypass and is already being exploited in active attacks. This latest threat represents part of an ongoing pattern of SharePoint vulnerabilities being targeted by threat actors in the wild.