CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

2026-06-25T01:24:14Z2939868d91463a01863416b25b08977c314d9b97fa3e83de088490e735faafd1
CISACVE-2025-67038CVE-2026-20230CVE-2026-4020Cisco Unified CMCordycepsDifyTapFortiBleedGitHub actions/checkoutGravity SMTPLantronix EDS5000ShapedPlugin backdoorSquidbleedactive exploitationcode injectioncredential harvestingmalicious npm packagesproof-of-concept exploitpwn requestsupply chain

What happened

The feed highlights multiple high‑impact incidents and active exploitations: CISA warned of active exploitation of a critical code‑injection flaw in Lantronix EDS5000 (CVE-2025-67038, CVSS 9.8) and urged immediate patching; a separate critical Cisco Unified CM vulnerability (CVE-2026-20230, CVSS 8.6) is being exploited after a public PoC; and threat actors are exploiting a Gravity SMTP WordPress flaw (CVE-2026-4020) to exfiltrate API keys. Large-scale campaigns and supply‑chain issues were also reported — FortiBleed credential harvesting targeting FortiGate devices (hundreds of thousands of FX

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2939868d91463a01863416b25b08977c314d9b97fa3e83de088490e735faafd1
Enrichment time
2026-06-25T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.