ForreastForreast

Forreast Intelligence Report

Intelligence Brief: CISA KEV

Generated August 16, 2026· Confidence: high· Type: vulnerability_assessment· Forreast Score: 81.4

Executive Summary

10 qualified signals detected: - [cisa_kev] CISA KEV: CVE-2021-21985 — VMware vCenter Server Improper Input Validation Vulnerability (VMware vCenter Server) - [cisa_kev] CISA KEV: CVE-2020-25213 — WordPress File Manager Plugin Remote Code Execution Vulnerability (WordPress File Manager Plugin) - [cisa_kev] CISA KEV: CVE-2019-9978 — WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability (WordPress Social Warfare Plugin) - [cisa_kev] CISA KEV: CVE-2020-29583 — Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability (Zyxel Multiple Products) - [cisa_kev] CISA KEV: CVE-2020-4006 — Multiple VMware Products Command Injection Vulnerability (VMware Multiple Products) ... and 5 more

Intelligence Brief: CISA KEV

Generated: 2026-08-16T17:10:05.128698+00:00

Entity: CISA KEV

Overview

This intelligence brief covers 10 qualified signals attributed to this entity.

Signal Details (Top 10)

CISA KEV: CVE-2021-21985 — VMware vCenter Server Improper Input Validation Vulnerability (VMware vCenter Server)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2021-21985 in VMware vCenter Server. VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution
  • CISA KEV: CVE-2020-25213 — WordPress File Manager Plugin Remote Code Execution Vulnerability (WordPress File Manager Plugin)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2020-25213 in WordPress File Manager Plugin. WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
  • CISA KEV: CVE-2019-9978 — WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability (WordPress Social Warfare Plugin)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2019-9978 in WordPress Social Warfare Plugin. WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
  • CISA KEV: CVE-2020-29583 — Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability (Zyxel Multiple Products)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2020-29583 in Zyxel Multiple Products. Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
  • CISA KEV: CVE-2020-4006 — Multiple VMware Products Command Injection Vulnerability (VMware Multiple Products)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2020-4006 in VMware Multiple Products. VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configu
  • CISA KEV: CVE-2020-10189 — Zoho ManageEngine Desktop Central File Upload Vulnerability (Zoho ManageEngine)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2020-10189 in Zoho ManageEngine. Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
  • CISA KEV: CVE-2019-8394 — Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability (Zoho ManageEngine)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2019-8394 in Zoho ManageEngine. Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
  • CISA KEV: CVE-2021-40539 — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability (Zoho ManageEngine)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2021-40539 in Zoho ManageEngine. Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
  • CISA KEV: CVE-2020-11738 — WordPress Snap Creek Duplicator Plugin File Download Vulnerability (WordPress Snap Creek Duplicator Plugin)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2020-11738 in WordPress Snap Creek Duplicator Plugin. WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their
  • CISA KEV: CVE-2021-27561 — Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability (Yealink Device Management)

  • Type: cyber_incident
  • Source: cisa_kev
  • Confidence: 0.9
  • Detected: 2026-08-12 06:39:52.202150+00:00
  • Summary: CISA Known Exploited Vulnerability: CVE-2021-27561 in Yealink Device Management. Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
  • Feedback & Clarifications

    We welcome your feedback and clarification requests. Your input helps us improve our intelligence delivery.

    Feedback & Clarification

    Share feedback on this report or request a clarification — one message, one place.

    ForreastForreast

    1207 Delaware Ave, Wilmington, DE 19806, USA

    The sovereign intelligence partner. Delivered by the Forreast team.

    © 2026 Forreast. This report is confidential and intended for the named recipient only. Link expires on September 23, 2026.