
🚨 CISA WARNS: TWO MORE VULNERABILITIES ARE BEING ACTIVELY EXPLOITED CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The newly added vulnerabilities are: * CVE-2021-3129 — Laravel Framework Ignition File Upload Vulnerability A vulnerability affecting Laravel applications using vulnerable versions of the Ignition error-page component. Under certain configurations, an unauthenticated remote attacker can abuse Ignition functionality to achieve remote code execution. * CVE-2026-24858 — Fortinet FortiOS/FortiProxy/FortiSwitchManager/FortiManager Authentication Bypass Vulnerability An authentication-bypass vulnerability affecting multiple Fortinet products that could allow an unauthenticated attacker with a FortiCloud account and registered device to log into other devices registered to different accounts. CISA added both vulnerabilities to KEV because they meet one of the most important criteria defenders should pay attention to: ⚠️ EVIDENCE OF ACTIVE EXPLOITATION. Federal Civilian Executive Branch agencies are required under BOD 22-01 to remediate KEV vulnerabilities by CISA's specified deadlines. But KEV should not be treated as a federal-government-only patch list. ⚠️ Analyst Note: The Laravel vulnerability is particularly interesting because CVE-2021-3129 is more than five years old. Its appearance in KEV again demonstrates an uncomfortable reality: Attackers don't necessarily need new zero-days. Internet-facing systems running old, exploitable software can remain valuable targets YEARS after a vulnerability becomes publicly known. The Fortinet vulnerability highlights a different problem: compromise of edge infrastructure. Firewalls, VPN gateways, management appliances and other perimeter devices sit at highly privileged positions in enterprise networks. When vulnerabilities in these systems become actively exploited, remediation should be treated as a priority rather than simply another item in the vulnerability-management queue. If either product exists in your environment, don't prioritize solely by CVSS. Prioritize by exploitation. Source: CISA — August 31, 2026 https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog #DDW #CISA #KEV #Fortinet #CyberSecurity
Post summary
CISA reports that two CVEs, CVE-2021-3129 and CVE-2026-24858, are actively exploited, urging defenders to immediately remediate.




