CISA Adds Four Known Exploited... Note

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. These include vulnerabilities in Adobe Commerce and Magento, two in Microsoft Windows, and one in N-able N-central. These vulnerabilities represent significant risks as they are common attack vectors for malicious actors. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog on publicly exposed assets. The directive requires agencies to implement risk-based vulnerability management to address high-risk vulnerabilities rapidly. It also sets expectations for how agencies should check for compromises before applying patches. Although BOD 26-04 applies specifically to FCEB agencies, CISA strongly recommends that all organizations adopt similar risk-based approaches to vulnerability management. CISA will continue to add vulnerabilities to the KEV Catalog as they are identified and meet the established criteria. Organizations can nominate exploited vulnerabilities not yet in the catalog by providing a CVE ID, evidence of exploitation, and clear mitigation guidance.