CISA Adds Four Known Exploited... Note

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new vulnerabilities, each showing signs of active exploitation. These additions include a double free vulnerability in Microsoft IKE Service Extensions and a weak authentication flaw in Microsoft SharePoint. Broadcom's VMware vCenter has a new path traversal vulnerability, and Apple macOS users face an improper authentication vulnerability. Such vulnerabilities are commonly targeted by cyber attackers and pose significant threats to federal systems.Binding Operational Directive (BOD) 26-04 mandates rigorous vulnerability management for Federal Civilian Executive Branch (FCEB) agencies. This directive emphasizes the critical role of the KEV Catalog in guiding remediation efforts. Federal agencies must quickly address high-risk vulnerabilities, particularly those in the KEV Catalog, especially on public-facing assets where exploitation could grant full control. The directive also sets expectations for agencies to check for system compromises before patching.Although BOD 26-04 specifically targets FCEB agencies, CISA strongly recommends that all organizations adopt a risk-based approach to vulnerability management. Prioritizing the remediation of KEV Catalog vulnerabilities is crucial for all entities. CISA will consistently add new vulnerabilities to the catalog if they meet the established criteria. Organizations aware of exploited vulnerabilities not yet listed in the KEV Catalog can nominate them for inclusion via CISA’s KEV Nomination Form. Nominated vulnerabilities must have a CVE ID, confirmed exploitation evidence, and clear mitigation advice.