U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
2026-04-26T02:51:46Z•29d05ec5cf1d5647fbf9967c0d3c17a4ed48e4f01160584e3802ceba94b290bf
BitwardenBreeze CacheCISACVE-2026-28950CVE-2026-3844CVE-2026-41651CheckmarxCisco ASAFIRESTARTER backdoorKnown Exploited VulnerabilitiesNCSCPack2TheRootRAMP ransomware marketplace leak','data breach','Rituals'Signal phishingWordPress pluginactive exploitationconsumer device botnetsfile uploadiOSnpm compromisepersistencepolitical targetingprivilege escalationproxy networksupply chain
What happened
Feed of mid-April 2026 security events: CISA added multiple known-exploited flaws (including CVE-2024-7399) to its KEV catalog. Active exploitation observed against the Breeze Cache WordPress plugin (CVE-2026-3844, CVSS 9.8) allowing unauthenticated file uploads and impacting hundreds of thousands of sites; Wordfence recorded hundreds of attacks. A long-standing local privilege-escalation bug in PackageKit (Pack2TheRoot, CVE-2026-41651, CVSS 8.8) and an iOS Notification Services issue (CVE-2026-28950) were disclosed and patched. CISA reported the FIRESTARTER backdoor persisting on a Cisco Fire
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 29d05ec5cf1d5647fbf9967c0d3c17a4ed48e4f01160584e3802ceba94b290bf
- Enrichment time
- 2026-04-26T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.