CISA Adds Five Known Exploited... Note

CISA Adds Five Known Exploited Vulnerabilities to Catalog

CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These include vulnerabilities in GNU Bash, Juniper ScreenOS, Jenkins, Smartembedded Meteobridge, and Samsung mobile devices. These types of vulnerabilities are frequently used by malicious actors and present significant risks to government networks. The KEV Catalog, established by Binding Operational Directive 22-01, lists vulnerabilities with substantial risk to the federal enterprise. Federal Civilian Executive Branch (FCEB) agencies are mandated to fix these vulnerabilities by a specific deadline. This directive aims to protect FCEB networks from actively exploited threats. Although the directive specifically targets FCEB agencies, CISA strongly advises all organizations to address KEV Catalog vulnerabilities. Prioritizing their remediation is crucial for reducing exposure to cyberattacks. Organizations should incorporate KEV remediation into their ongoing vulnerability management strategies. CISA will continue to update the KEV Catalog with new vulnerabilities that meet defined criteria.