CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
2026-06-25T01:24:14Z•2939868d91463a01863416b25b08977c314d9b97fa3e83de088490e735faafd1
CISACVE-2025-67038CVE-2026-20230CVE-2026-4020Cisco Unified CMCordycepsDifyTapFortiBleedGitHub actions/checkoutGravity SMTPLantronix EDS5000ShapedPlugin backdoorSquidbleedactive exploitationcode injectioncredential harvestingmalicious npm packagesproof-of-concept exploitpwn requestsupply chain
What happened
The feed highlights multiple high‑impact incidents and active exploitations: CISA warned of active exploitation of a critical code‑injection flaw in Lantronix EDS5000 (CVE-2025-67038, CVSS 9.8) and urged immediate patching; a separate critical Cisco Unified CM vulnerability (CVE-2026-20230, CVSS 8.6) is being exploited after a public PoC; and threat actors are exploiting a Gravity SMTP WordPress flaw (CVE-2026-4020) to exfiltrate API keys. Large-scale campaigns and supply‑chain issues were also reported — FortiBleed credential harvesting targeting FortiGate devices (hundreds of thousands of FX
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2939868d91463a01863416b25b08977c314d9b97fa3e83de088490e735faafd1
- Enrichment time
- 2026-06-25T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.