Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns

CISA added CVE-2023-22894 (Strapi Strapi) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL)…

Excerpt from the primary source: CISA Known Exploited Vulnerabilities

Who is affected

Security professionals

Affected technology: Strapi

Why it matters

CISA lists this as exploited in the wild. Unpatched Strapi systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Patch

Apply the vendor's security update for Strapi. Check the linked advisory for affected and fixed versions, and put internet-facing systems first.

CISA's required action for CVE-2023-22894: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 11, 2026.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns CISA Known Exploited Vulnerabilities · cisa.gov · Oct 8, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

Making sure the checks get printed

Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.

Severity: HighAction: Patch

Cisco Patches a Dozen Critical Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Patch

Apply the vendor's security update for Cisco networking & security.

Severity: ElevatedAction: Be aware

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.