Multiple vulnerabilities in Zyxel, North Grid Proself, ProjectSend, and CyberPanel are being actively exploited in the wild.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added these flaws to its Known Exploited Vulnerabilities (KEV) list.
The most critical vulnerability is an incorrect default permissions flaw in CyberPanel, rated 10/10 in severity.
Chinese state-sponsored threat actors have been exploiting some of these vulnerabilities, including the XML External Entity (XEE) reference vulnerability in Proself.