CISA | Alerts
Follow
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities are actively being exploited by malicious actors and pose significant risks. The newly added vulnerabilities include heap-based buffer overflows in Fortinet products and authentication bypasses in Citrix NetScaler and Cisco Firewall Management Center. A Google Chromium V8 out-of-bounds write vulnerability has also been added. These types of vulnerabilities are common attack vectors. Binding Operational Directive 26-04 mandates that Federal Civilian Executive Branch agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive emphasizes rapid patching of high-risk vulnerabilities on publicly exposed assets. It also sets expectations for agencies to check for compromises before applying patches. While this directive applies only to federal agencies, CISA urges all organizations to implement risk-based vulnerability management. CISA will continue to add vulnerabilities to the KEV Catalog as they are identified and exploited. Organizations can nominate potential KEV additions with a CVE ID, exploitation evidence, and mitigation guidance.