Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: CISA confirms active exploitation of four enterprise software bugs

Cybersecurity Threats: Four Enterprise Software Bugs Actively Exploited

Cybersecurity Threats: Four Enterprise Software Bugs Actively Exploited

In a recent warning, the Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. highlighted four vulnerabilities that are currently being exploited by hackers, impacting various enterprise software solutions.

Vulnerabilities Impacting Versa and Zimbra

Two of these vulnerabilities affect enterprise software from Versa and Zimbra. The first one, CVE-2025-31125, is a high-severity improper access control issue that can expose non-allowed files when the server is explicitly exposed to the network. This issue affects specific versions of Versa and Zimbra software and has been patched in certain releases.

Vulnerabilities in Vite and Prettier

The other two vulnerabilities affect the Vite frontend tooling framework and the Prettier code formatter. One of these vulnerabilities, CVE-2025-54313, was caused by a supply-chain compromise and affected the eslint-config-prettier package. Hackers hijacked several popular JavaScript libraries, including this package, and published on npm versions embedded with malicious code.

Relevance to North East India and Broader Indian Context

These vulnerabilities pose a significant risk to organizations worldwide, including those in North East India. As businesses increasingly rely on digital platforms, understanding and addressing cybersecurity threats is crucial to protect sensitive data and maintain business continuity.

Versa Concerto SD-WAN Orchestration Platform Vulnerability

CISA also marked another bug, CVE-2025-34026, as exploited. This critical-severity authentication bypass vulnerability affects the Versa Concerto SD-WAN orchestration platform and is caused by a Traefik reverse proxy misconfiguration.

Zimbra Collaboration Suite Webmail Classic UI Vulnerability

Lastly, CISA warned of CVE-2025-68645 being exploited, a local file inclusion vulnerability in the Webmail Classic UI of Zimbra Collaboration Suite 10.0 and 10.1. This bug is caused by improper handling of user-supplied parameters in the RestFilter servlet.

Implications and Mitigations

Federal agencies bound by the BOD 22-01 directive are now required to apply available security updates or vendor-suggested mitigations, or to stop using the products by February 12, 2026. CISA has not shared any details about the exploitation activity, and the status of the flaws used in ransomware attacks remains unknown.

2026 CISO Budget Benchmark

As we move into 2026, it's budget season! Over 300 CISOs and security leaders have shared their plans, spending, and priorities for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities.