U.S. CISA adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog

2026-06-05T02:51:50Z73362ab63a17a98ced3038ec171bb5ec46bdb26f2a10d144e294506d0de7d8dd
AndroidCISACVE-2025-48595CVE-2026-0826CVE-2026-20230CVE-2026-45247CiscoGamaredonGoogle patchHP PolyKEVMirasvitOperation KRATOSOutlook compromiseSSRFTelegram-C2VS Code zero-dayVoIPWinRARespionageknown-exploited-vulnerabilitiesmodular-malwarenear-filelesspublic-PoCroot-RCE

What happened

Multiple high/critical vulnerabilities and active threat developments were reported. CISA added the Mirasvit Full Page Cache Warmer flaw (CVE-2026-45247, CVSS 9.3) to its Known Exploited Vulnerabilities (KEV) catalog. Cisco patched a critical Unified CM flaw (CVE-2026-20230) with public PoC that enables unauthenticated SSRF. Rapid7 disclosed a critical unauthenticated stack-buffer overflow in HP Poly VoIP phones (CVE-2026-0826) leading to possible root RCE. Google’s June Android updates fix an actively exploited privilege-escalation bug (CVE-2025-48595). Separately, Gamaredon is exploiting a (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
73362ab63a17a98ced3038ec171bb5ec46bdb26f2a10d144e294506d0de7d8dd
Enrichment time
2026-06-05T02:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog · Baitaphish