Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2023-27351 (CVSS score: 8.2) - An improper authentication vulnerability in PaperCut
Analysis Summary
This summary focuses on the critical vulnerabilities recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog based on the provided report.
# Vulnerability: Multiple Flaws in Infrastructure and Management Software
## CVE Details
- **CVE-2025-32975**: 10.0 (Critical) | CW-287 (Improper Authentication)
- **CVE-2023-27351**: 8.2 (High) | CWE-287 (Improper Authentication)
- **CVE-2026-20128**: 7.5 (High) | CWE-312 (Storing Passwords in Recoverable Format)
- **CVE-2024-27199**: 7.3 (High) | CWE-22 (Relative Path Traversal)
- **CVE-2025-2749**: 7.2 (High) | CWE-22 (Path Traversal)
- **CVE-2026-20133**: 6.5 (Medium) | CWE-200 (Exposure of Sensitive Information)
- **CVE-2025-48700**: 6.1 (Medium) | CWE-79 (Cross-Site Scripting)
- **CVE-2026-20122**: 5.4 (Medium) | CWE-250 (Incorrect Use of Privileged APIs)
## Affected Systems
- **PaperCut**: NG/MF (specifically the `SecurityRequestFilter` class)
- **Cisco**: Catalyst SD-WAN Manager (vManage)
- **Quest**: KACE Systems Management Appliance (SMA)
- **JetBrains**: TeamCity (On-premise versions)
- **Synacor**: Zimbra Collaboration Suite (ZCS)
- **Kentico**: Xperience CMS (Staging Sync Server)
## Vulnerability Description
The vulnerabilities span several technical categories:
1. **Authentication Bypass**: Improperly implemented filters in PaperCut and Quest SMA allow attackers to bypass security checks or impersonate users without valid credentials.
2. **Path Traversal**: Flaws in TeamCity and Kentico allow attackers to access or upload data to unauthorized file locations.
3. **Privilege Escalation**: Cisco SD-WAN flaws allow attackers to leverage privileged APIs or recoverable credential files to gain `vmanage` or `DCA` user permissions.
4. **Information Disclosure**: Exposure of sensitive info and XSS in Zimbra allow for session hijacking and unauthorized data access.
## Exploitation
- **Status**: **Exploited in the Wild**.
- CVE-2023-27351 (PaperCut) has been weaponized by "Lace Tempest" for Cl0p and LockBit ransomware.
- CVE-2025-32975 (Quest) is actively targeted by unknown actors.
- Cisco Catalyst flaws (CVE-2026-20122/20128) were confirmed exploited in March 2026.
- **Complexity**: Low to Medium.
- **Attack Vector**: Primarily Network (Remote), though CVE-2026-20128 requires Local access.
## Impact
- **Confidentiality**: High (Access to sensitive data, recovery of passwords)
- **Integrity**: High (Arbitrary file upload and overwriting)
- **Availability**: High (Full system takeover/Ransomware deployment)
## Remediation
### Patches
- **Cisco**: Updates available for Catalyst SD-WAN Manager.
- **Quest**: Patches released for KACE SMA.
- **PaperCut**: Updated versions of NG/MF mitigate the filter bypass.
- **JetBrains**: Apply the latest security updates for TeamCity on-premise.
### Workarounds
- CISA mandates Federal agencies to remediate Cisco flaws by **April 23, 2026**, and others by **May 4, 2026**.
- Isolate management interfaces (vManage, TeamCity, PaperCut) from the public internet.
## Detection
- **Indicators of Compromise**: Monitor for unauthorized access to the `SecurityRequestFilter` class in PaperCut logs. Look for unexpected file uploads in Cisco `vmanage` directories.
- **Detection Tools**: Utilize vulnerability scanners updated with the latest KEV definitions and monitor for Arctic Wolf/CISA threat advisories regarding Quest SMA weaponization.
## References
- CISA KEV Catalog: hxxps[://]www.cisa.gov/known-exploited-vulnerabilities-catalog
- Cisco Advisory: hxxps[://]sec.cloudapps.cisa.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
- PaperCut Security: hxxps[://]www.papercut.com/kb/Main/Security-Bulletin-April-2023/