CISA Adds Four Known Exploited... Note

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The newly listed vulnerabilities include issues in DD-WRT, Langflow, and two in WordPress Core. These types of vulnerabilities are common attack methods for cybercriminals and present considerable dangers to federal systems. Binding Operational Directive 26-04 mandates that Federal Civilian Executive Branch agencies prioritize security updates based on risk. This directive emphasizes the KEV Catalog and requires agencies to quickly fix high-risk vulnerabilities listed there on exposed assets. It also sets expectations for checking systems for compromise before applying patches. Although BOD 26-04 specifically targets FCEB agencies, CISA advises all organizations to implement risk-based vulnerability management. Prioritizing the remediation of KEV Catalog vulnerabilities is strongly recommended for everyone. CISA will continue to update the KEV Catalog with newly identified exploited vulnerabilities. Organizations can nominate vulnerabilities not yet in the KEV Catalog if they have a CVE ID, proof of exploitation, and clear mitigation steps.