• News/
  • https://www.bleepingcomputer.com/news/security/cisa-confirms-active-exploitation-of-four-enterprise-software-bugs/

CISA confirms active exploitation of four enterprise software bugs

BleepingComputer
·
Bill Toulas
·
Published Jan 23, 2026
·
Updated

The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. warned of active exploitation of four vulnerabilities impacting enterprise software from Versa and Zimbra, the Vite frontend tooling framework, and the Prettier code formatter. The security issues have been added to CISA’s KEV (Known Exploited Vulnerabilities) catalog, indicating that the agency has evidence that hackers are exploiting them in the wild. One of the vulnerabilities is CVE-2025-31125, a high-severity improper access control issue disclosed in March last year that can be exploited to expose non-allowed files when the server is explicitly exposed to the network. The issue affects only exposed dev instances and has been patched in versions 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11. Another bug CISA marked as exploited is CVE-2025-34026, a critical-severity authentication bypass in the Versa Concerto SD-WAN orchestration platform disclosed in May 2025. It is caused by a Traefik reverse proxy misconfiguration that allows access to administrative endpoints, including the internal Actuator endpoint, exposing heap dumps and trace logs. Affected products are Concerto 12.1.2 through 12.2.0, although additional versions may also be impacted. Researchers at cybersecurity company ProjectDiscovery reported the issues to the vendor on February 13, 2025, and Versa Concerto confirmed to BleepingComputer that they had fixed them on March 7, 2025. The US cybersecurity agency also lists CVE-2025-54313 as levera...

Read full article

Affected Software

4 affected components
Versa Concerto>=12.1.2<=12.2.0
Zimbra Collaboration Suite>=10.0<=10.1
eslint-config-prettier eslint-config-prettier=8.10.1, =9.1.1, =10.1.6, =10.1.7
Versa Various=6.2.4, =6.1.3, =6.0.13, =5.4.16, =4.5.11
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the main vulnerabilities confirmed by CISA?

CISA confirmed active exploitation of vulnerabilities in Versa Concerto, Zimbra Collaboration Suite, and eslint-config-prettier.

2

Which specific software versions are impacted by these vulnerabilities?

Versa Concerto versions 12.1.2 to 12.2.0, Zimbra Collaboration Suite versions 10.0 to 10.1, and specific versions of eslint-config-prettier including 8.10.1 and 10.1.7 are affected.

3

What type of organizations should be concerned about these vulnerabilities?

Organizations using the affected enterprise software, particularly those relying on Versa or Zimbra products, should be concerned and take immediate action.

4

What actions should users of the affected software consider taking?

Users should prioritize updating their software to the latest versions and implement security measures to mitigate potential exploitation.

5

Is there any indication of the severity of these vulnerabilities?

The article implies a high severity level due to confirmed active exploitation, necessitating urgent attention from affected users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203