CISA | Alerts
Follow
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new vulnerabilities, confirmed to be actively exploited. These include path traversal flaws in Samsung MagicINFO 9 Server and SimpleHelp, a missing authorization issue in SimpleHelp, and a command injection vulnerability in D-Link DIR-823X. Such vulnerabilities are commonly exploited by malicious actors, posing substantial risks to federal systems. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01 to address significant cyber risks to the federal enterprise. This directive mandates Federal Civilian Executive Branch (FCEB) agencies to remediate listed vulnerabilities by specified deadlines. This action is crucial for safeguarding FCEB networks from ongoing cyber threats. While BOD 22-01 primarily targets FCEB agencies, CISA strongly advises all organizations to prioritize KEV Catalog remediation. Timely patching of these vulnerabilities is a critical component of effective vulnerability management practices. CISA remains committed to continuously updating the catalog with new vulnerabilities that meet its defined criteria.