CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a new vulnerability, CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This cross-site request forgery vulnerability in Cisco IOS is a common attack vector that poses significant risks. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets. This directive requires agencies to address vulnerabilities that grant total control post-exploitation promptly. BOD 26-04 also outlines when agencies must check for compromises before applying patches. While this directive specifically targets FCEB agencies, CISA recommends that all organizations implement risk-based vulnerability management. They urge all entities to prioritize the remediation of vulnerabilities found in the KEV Catalog. CISA will continue to add vulnerabilities to the KEV Catalog that meet the established criteria. Organizations aware of exploited vulnerabilities not yet in the catalog can submit them for consideration. Such submissions require a CVE ID, proof of exploitation, and clear mitigation steps.