Visualização de leitura

G7, CISA Urge Urgent Shift to Post-Quantum Cryptography

post-quantum cryptography

Some of the world's leading democracies are pushing governments and companies to start preparing for post-quantum cryptography before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today.

In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said organizations should begin their transition to post-quantum cryptography now, rather than waiting until cryptographically relevant quantum computers (CRQCs) are available to threat actors.

Why the Post-Quantum Cryptography Shift Cannot Wait

The publication, titled "Preparing for the Post-Quantum Era: A Call to Action," warns that the quantum computing threat is no longer a distant concern. While the exact timeline for CRQC development remains uncertain, the working group said recent technological advances suggest such machines could emerge sooner than expected, putting widely used public-key cryptography mechanisms at risk.

One of the most immediate dangers is a tactic known as "harvest now, decrypt later," where malicious actors intercept and store encrypted data today with the intention of decrypting it once a CRQC becomes available. This poses a serious risk to governmental records, sensitive personal data, and trade or business secrets that require long-term confidentiality.

The advisory also cautions that CRQCs could eventually be used to target authentication mechanisms, allowing bad actors to impersonate trusted entities, forge data, or compromise equipment. Because supply chain vulnerabilities can cascade, a single organization's delay in adopting post-quantum cryptography could expose entire sectors to compromise.

According to the report, organizations that fail to act may also face business consequences beyond security risk, including exclusion from public procurement contracts and loss of competitive advantage.

Five Priorities for the PQC Transition

The G7 Cybersecurity Working Group outlined five priority areas to guide the global shift toward post-quantum cryptography:

  1. Raising awareness — Many organizations still view the quantum threat as a distant or purely technical issue. The group called for awareness campaigns, technical guidance, and workforce upskilling to reframe it as an economic and business risk.
  2. Developing national strategies — Countries are encouraged to build strategies that ensure an adequate supply of quantum-safe hardware and software while encouraging adoption, integrating the effort into broader digital privacy and security policies.
  3. Advancing research and development — Governments should fund research programs and support pilot projects and testbeds to help organizations test and refine their transition to post-quantum cryptography.
  4. Building public-private partnerships — Collaboration between government, industry, and academia is seen as key to developing domestic expertise, lowering transition costs, and sharing playbooks and case studies across sectors.
  5. Integrating PQC into cybersecurity requirements — The group recommends treating post-quantum cryptography adoption as a natural evolution of cryptographic best practice, and embedding requirements into public procurement to push both vendors and organizations toward quantum-safe systems.

The advisory emphasizes that the shift to post-quantum cryptography cannot be solved by individual organizations in isolation. Instead, it calls for early engagement, coordinated planning, and informed decision-making across public and private sectors worldwide.

Tackling the risks that the impending quantum computing era poses to current cryptographic systems... requires a coordinated global effort to transition to PQC," the report states, adding that public and private organizations must act now to safeguard confidential data, supply chains, and critical systems.

The document was jointly published by cybersecurity authorities from Canada, Germany, Italy, Japan, the United Kingdom, the United States, and France's ANSSI, with participation from the European Commission and support from the EU Agency for Cybersecurity (ENISA).

CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation

CVE-2026-15409

Security researchers have identified two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting SonicWall SMA1000 Series appliances. The flaws are already being exploited in the wild, prompting urgent warnings from SonicWall and CISA. Successful exploitation could result in Remote Code Execution, bypass of security restrictions, and broader compromise of affected systems.  The vulnerabilities impact SonicWall SMA1000 models 6210, 7210, and 8200v running versions 12.4.3-03245, 12.4.3-03387, 12.4.3-03434 (platform-hotfix), 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800 (platform-hotfix). 

CVE-2026-15409 and CVE-2026-15410 Explained 

CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. According to SonicWall, an unauthenticated remote attacker could force the appliance to send requests to unintended locations. The flaw carries a CVSS v3 score of 10.0 with the vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and is mapped to CWE-918.  CVE-2026-15410 is a post-authentication code injection vulnerability in the SMA1000 Appliance Management Console (AMC). Under specific conditions, a remote authenticated attacker with administrator privileges could execute arbitrary operating system commands, enabling Remote Code Execution. The vulnerability has a CVSS score of 7.2, uses the vector CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, and is associated with CWE-94. 

Active Exploitation and Impact 

SonicWall confirmed that CVE-2026-15409 and CVE-2026-15410 are being actively exploited. The advisory states, "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities."  The vulnerabilities may allow Remote Code Execution and bypass of security restrictions, increasing the risk of unauthorized system access. 

Fixed Versions and Detection Guidance 

SonicWall has released fixes in 12.4.3-03453 (platform-hotfix) and later, and 12.5.0-02835 (platform-hotfix) and later. The company noted that these issues do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.  Administrators are advised to inspect extraweb_access.log for HTTP 200 requests to /api/login or /api/logout, suspicious /wsproxy requests returning HTTP 101, ctrl-service.log entries indicating hotfix rollbacks with path traversal names, and unauthorized /api/login or /api/logout routes in /var/lib/unit/conf.json.  If indicators of compromise are found, SonicWall recommends re-imaging hardware appliances or redeploying virtual appliances, changing user and administrator passwords, and resetting TOTP tokens after performing a forensic investigation.  The advisory, SNWLID-2026-0008, was first published and last updated on July 14, 2026. The vulnerabilities were internally discovered by Adam Babis of SonicWall PSIRT, while Sean Koessel and Steven Adair of Volexity were credited in Version 1.1 for helping identify an additional indicator of compromise during the investigation. On the same day, CISA added the vulnerabilities to its Known Exploited Vulnerabilities Catalog. 

CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks

CISA vulnerability management directive

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-04, the new CISA vulnerability management directive replaces older remediation requirements with a framework designed to prioritize vulnerabilities that pose the greatest risk to government systems. The move comes as cybersecurity officials warn that artificial intelligence is helping threat actors identify and exploit security flaws faster than ever before. The directive aims to improve federal cyber resilience while ensuring agencies focus resources on threats most likely to be exploited.

New Risk-Based Model for Vulnerability Remediation

Under the directive, federal civilian agencies must evaluate vulnerabilities against four key criteria: According to CISA officials, vulnerabilities meeting three of these four conditions will face accelerated remediation deadlines. The strictest requirement applies to vulnerabilities that are actively exploited, can be automated, and affect internet-facing systems. Agencies must patch such vulnerabilities within 72 hours. In cases where exploitation could allow attackers to gain complete control of a system, agencies are also required to investigate whether a compromise has already occurred before applying security updates. For vulnerabilities that meet similar risk criteria but cannot be exploited automatically, agencies will have up to 14 days to complete remediation, provided attackers have not already achieved full system control. Federal agencies have been given 180 days to update their internal policies and adopt the new timelines.

CISA Vulnerability Management Directive Responds to AI-Driven Cyber Threats

A key driver behind the CISA vulnerability management directive is the growing concern that artificial intelligence is reducing the time between the release of a security patch and active exploitation by threat actors. CISA noted that cybercriminals are increasingly leveraging AI-powered tools to discover, analyze, and exploit vulnerabilities more efficiently. As a result, defenders have less time to respond once a vulnerability becomes public. The agency said the new framework reflects today's threat environment by considering not only the vulnerability itself but also attacker capabilities, exploitability, asset exposure, and the potential consequences of a successful attack. By combining these factors, CISA aims to help agencies make informed remediation decisions without overwhelming IT teams with unnecessary patching activities.

Directive Consolidates Existing Federal Requirements

The new directive harmonizes and updates requirements from two previous federal cybersecurity mandates:
  • BOD 19-02, which focused on vulnerability remediation for internet-accessible systems
  • BOD 22-01, which addressed risks associated with Known Exploited Vulnerabilities (KEV)
Rather than treating all vulnerabilities equally, the updated approach prioritizes those most likely to be weaponized by attackers. Acting CISA Director Nick Andersen said the directive is intended to help agencies focus on areas of highest risk while improving transparency, predictability, and resource planning for remediation efforts. The agency also encouraged organizations outside the federal government to adopt similar risk-based vulnerability management practices.

Agencies Must Check for Compromise Before Patching

One of the most significant additions in the new directive is the requirement for agencies to determine whether a vulnerable system has already been compromised before applying patches. CISA emphasized that installing a security update does not automatically remove attackers who may already have gained access to a network. As a result, agencies must assess when and how a compromise occurred and conduct appropriate investigations before remediation. This requirement reflects growing concerns that attackers often maintain persistence inside networks even after vulnerabilities are patched. The agency described compromise assessment as a critical component of effective cybersecurity risk management, particularly for vulnerabilities already known to be exploited in the wild.

Strengthening Federal Cybersecurity Readiness

The CISA vulnerability management directive aligns with broader U.S. government efforts to strengthen cybersecurity and secure federal information systems against increasingly sophisticated threats. The directive supports objectives outlined in the Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security, which calls for enhanced protection of civilian federal networks. As agencies implement the new requirements, CISA will monitor compliance, track progress, and provide support where necessary. The agency said the initiative represents an important step toward reducing cybersecurity risk across the federal enterprise while ensuring faster responses to the vulnerabilities most likely to be targeted by attackers.

CISA Adds 8 Exploited Vulnerabilities Affecting Cisco, Zimbra, TeamCity

KEV catalog

The Cybersecurity and Infrastructure Security Agency (CISA) have expanded its Known Exploited Vulnerabilities, commonly referred to as the KEV catalog, with eight newly identified security flaws that are currently being exploited in real-world attacks. The update was announced on April 21, 2026.  CISA’s latest update to the KEV catalog introduces eight vulnerabilities spanning a range of products and vendors. Among the most notable inclusions are CVE-2023-27351 and CVE-2024-27199, both of which have drawn attention due to their active exploitation and potential impact on enterprise environments. 

Latest Vulnerabilities Added to the KEV Catalog 

  • CVE-2023-27351 (CVSS 8.2): An improper authentication flaw affecting PaperCut NG/MF. This issue allows attackers to bypass authentication mechanisms via the SecurityRequestFilter class.  
  • CVE-2024-27199 (CVSS 7.3): A relative path traversal vulnerability in JetBrains TeamCity that could enable attackers to carry out limited administrative actions.  
  • CVE-2025-2749 (CVSS 7.2): A path traversal flaw in Kentico Xperience, permitting authenticated users to upload arbitrary data to specific paths via the Staging Sync Server.  
  • CVE-2025-32975 (CVSS 10.0): A critical improper authentication vulnerability in Quest KACE Systems Management Appliance (SMA), enabling attackers to impersonate legitimate users without credentials.  
  • CVE-2025-48700 (CVSS 6.1): A cross-site scripting (XSS) issue in Zimbra Collaboration Suite that allows execution of arbitrary JavaScript within a user session.  
  • CVE-2026-20122CVE-2026-20128, and CVE-2026-20133: Three distinct vulnerabilities impacting Cisco Catalyst SD-WAN Manager, ranging from privilege escalation to exposure of sensitive information.  

Cisco Catalyst Vulnerabilities Under Active Exploitation 

Three of the eight newly listed flaws affect Cisco Catalyst SD-WAN Manager, denoting concerns around enterprise networking infrastructure security. These vulnerabilities include: 
  • CVE-2026-20122 (CVSS 5.4): Improper use of privileged APIs, allowing attackers to upload or overwrite arbitrary files and gain elevated privileges.  
  • CVE-2026-20128 (CVSS 7.5): Storage of passwords in a recoverable format, enabling local attackers to extract credentials and escalate access.  
  • CVE-2026-20133 (CVSS 6.5): Exposure of sensitive information to unauthorized actors, potentially allowing remote attackers to access confidential system data.  

Continued Concerns Around CVE-2023-27351 and CVE-2024-27199 

The inclusion of CVE-2023-27351 in the KEV catalog is particularly significant given its history. In April 2023, exploitation of this vulnerability was linked to the Lace Tempest threat group, which used it to deploy Cl0p and LockBit ransomware. Its continued presence in active exploitation campaigns indicates that unpatched systems remain a viable target.  Similarly, CVE-2024-27199 follows an earlier related vulnerability, CVE-2024-27198, which was added to the KEV catalog in March 2024. While both affect JetBrains TeamCity, it remains unclear whether they are being exploited in tandem or by the same threat actors.

Zimbra Collaboration Suite Vulnerability Raises High-Risk Alert 

Another critical addition to the KEV catalog is CVE-2025-48700, affecting Zimbra Collaboration Suite. This vulnerability enables cross-site scripting attacks that can lead to unauthorized access to sensitive information. Security assessments classify this issue as High Risk, especially since it is already being exploited in the wild. 

Impact and Affected Versions 

The vulnerability impacts multiple versions of Zimbra Collaboration Suite, including: 
  • Versions prior to 9.0.0 Patch 43  
  • Versions prior to 10.0.12  
  • Versions prior to 10.1.4  
  • Versions prior to 8.8.15 Patch 47  
Attackers exploiting CVE-2025-48700 can inject malicious JavaScript into user sessions, potentially compromising sensitive data and enabling further attacks. 

Mitigation Measures 

To address this issue, users are advised to apply vendor-released patches: 
  • Version 9.0.0 Patch 43  
  • Version 10.0.12  
  • Version 10.1.4  
  • Version 8.8.15 Patch 47  
CISA recommends that organizations prioritize remediation efforts in line with KEV catalog guidance, especially vulnerabilities with confirmed exploitation activity. 

Federal Deadlines and Broader Implications 

With the addition of these vulnerabilities to the KEV catalog, CISA has also set remediation deadlines for federal agencies, spanning April to May 2026. These deadlines are part of Binding Operational Directive (BOD) requirements, which mandate timely patching of known exploited vulnerabilities.  The continued expansion of the KEV catalog, including high-profile entries like CVE-2023-27351, CVE-2024-27199, and Cisco Catalyst-related flaws, reflects a new threat landscape where attackers rapidly weaponize newly discovered weaknesses. Organizations beyond the federal sector are also encouraged to treat the KEV catalog as a priority reference for vulnerability management and risk mitigation. 
❌