Product

Strapi

Made by Strapi. 1 of its vulnerabilities are known to have been exploited.

Coverage

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns

CISA added CVE-2023-22894 (Strapi Strapi) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL)…

Why it matters

CISA lists this as exploited in the wild. Unpatched Strapi systems are exposed to active attacks now.

Patch

Apply the vendor's security update for Strapi.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. AdvisoryKEV

    Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

    Basis: CISA Cybersecurity Advisories (government advisory)

  2. AdvisoryKEV

    Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  3. Added to CISA KEVCVE-2023-22894

    CVE-2023-22894 added to CISA KEV: Strapi Strapi, Strapi Cleartext Storage of Sensitive Information Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited

Strapi Strapi

Strapi Cleartext Storage of Sensitive Information Vulnerability

Added Oct 8, 2026Fed. due Oct 11, 2026Coverage →