CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2025-7775, to its Known Exploited Vulnerabilities (KEV) Catalog. This Citrix NetScaler Memory Overflow Vulnerability has been observed to be actively exploited. Such vulnerabilities represent a common attack method for cybercriminals. They also present substantial risks to federal systems. The Binding Operational Directive (BOD) 22-01 established the KEV Catalog. This directive mandates federal civilian executive branch agencies to fix these identified vulnerabilities. The goal is to safeguard federal networks from active threats. While BOD 22-01 specifically targets FCEB agencies, CISA recommends all organizations address KEV Catalog vulnerabilities. Prioritizing the remediation of these vulnerabilities is crucial for improving cybersecurity. CISA will continue to update the catalog with vulnerabilities meeting established criteria.