Forenshield Critical Vulnerabilities in Umbraco CMS and Linux Kernel Exploited
Article Content
- •CVE-2020-9471 in Umbraco CMS has a CVSS score of 8.8 and is actively exploited.
- •CVE-2024-35789 affects the Linux kernel with a CVSS score of 7.8, also under active exploitation.
- •CVE-2026-87902 was added to the CISA KEV list due to confirmed exploitation.
Recent vulnerabilities CVE-2020-9471 and CVE-2024-35789 have been identified in Umbraco CMS and the Linux kernel, respectively. CVE-2020-9471, with a CVSS score of 8.8, was published on March 16, 2020, and affects multiple versions of Umbraco CMS. CVE-2024-35789, rated 7.8, was published on May 17, 2024, impacting various Linux distributions. Both vulnerabilities have been actively exploited, with CVE-2026-87902 recently added to the CISA KEV list on September 25, 2026. The exploitation methods include remote code execution and privilege escalation, posing significant risks to affected systems. Organizations using these platforms are urged to apply patches immediately to mitigate risks. The situation is evolving, with ongoing monitoring required for further developments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2020-9471 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation Cisco has disclosed a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via a flaw in an API endpoint. This vulnerability has a CVSS score of 10.0 and is actively being exploited in the wild, prompting Cisco to issue…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…