CISA | Alerts
Follow
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding five new vulnerabilities. These vulnerabilities include issues in SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows, and IGEL OS. Active exploitation evidence prompted the addition of these vulnerabilities to the catalog. These vulnerabilities represent common entry points for malicious cyber actors. They pose a significant risk to the federal enterprise and other organizations. Binding Operational Directive (BOD) 22-01 established the KEV Catalog for FCEB agencies. The directive requires agencies to remediate identified vulnerabilities by specific deadlines. Although BOD 22-01 applies to federal agencies, CISA recommends all organizations prioritize KEV remediation. Organizations should include timely remediation within their vulnerability management. CISA will continue to update the KEV catalog with new vulnerabilities.