VYPR
AI Brief2026-08-06· generated Aug 6, 2026

KEV Additions: Fortinet, Tomcat, Check Point Exploited

CISA flags actively exploited Fortinet, Apache Tomcat, and Check Point vulnerabilities, alongside critical flaws in Citrix, Ivanti, and Qlik.

A critical authentication bypass vulnerability in FortiOS and FortiProxy (CVE-2024-55591) is being actively exploited, allowing remote attackers to gain super-user privileges. This flaw affects FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. The Gentlemen ransomware group has been observed leveraging Fortinet exploits, and this vulnerability is a significant concern for organizations using these Fortinet products. The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks

CISA has added CVE-2026-34486, a critical encryption bypass vulnerability in Apache Tomcat, to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, affecting Tomcat versions 11.0.20, 10.1.53, and 9.0.116, allows attackers to bypass the EncryptInterceptor. Multiple security outlets have reported on this vulnerability, highlighting its active exploitation. CISA Adds Three Known Exploited Vulnerabilities to Catalog

CVE-2024-24919, a high-severity vulnerability in Check Point Security Gateways, is also being actively exploited. This flaw could allow an attacker to read certain information on gateways connected to the internet with Remote Access VPN or Mobile Access enabled. CISA has urged federal agencies to patch this vulnerability, and reports indicate it has been exploited by ransomware gangs. CISA orders feds to patch Check Point flaw exploited by ransomware gangs

Citrix Systems has a critical unauthenticated remote code execution vulnerability (CVE-2023-3519) that is actively exploited. This flaw poses a significant risk to organizations using Citrix products, as it allows for complete system compromise. The INC ransomware group has been observed using this vulnerability. INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Several other critical vulnerabilities have been added to the KEV catalog, including an authentication bypass in Ivanti EPMM (CVE-2023-35078), an HTTP Request Tunneling vulnerability in Qlik Sense Enterprise for Windows (CVE-2023-41265), and remote code execution in Array Networks SSL VPNs (CVE-2023-28461). These vulnerabilities represent a broad range of affected products and attack vectors, underscoring the need for diligent patching and security monitoring.

Synthesized by Vypr AI