CISA added new vulnerabilities with proven active exploitation - among them in Ubiquiti UniFi and SimpleHelp. This isn't theory. Someone is already using them. The patch doesn't wait.
- CISA added new actively exploited vulnerabilities to the KEV catalog, incl. Ubiquiti UniFi OS and SimpleHelp (June 29).
- KEV means proven exploitation in real attacks: the priority is 'now.'
- For US federal agencies the patch is mandatory within a deadline; for everyone else it's a guide to what to fix first.
This week CISA added several vulnerabilities to the actively-exploited catalog - with proof they're already used in real attacks. Among them - flaws in Ubiquiti UniFi OS (access control, path traversal, input validation) and an authentication bypass in SimpleHelp.
Why I'm running this - UniFi is equipment that a lot of people, small businesses and home labs keep right at the entrance to their network. A hole there isn't small. It's the gate to everything behind it.
CISA's list is a free priority list - it ranks for you what's already being exploited. Running UniFi or SimpleHelp? This is the first thing to fix this week.
The list shows priority (actively exploited now), not completeness - specific versions and patches should be checked with the vendor.