CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2025-57819, a Sangoma FreePBX Authentication Bypass Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability has been confirmed to be actively exploited by malicious cyber actors. Authentication bypass vulnerabilities are a common attack method that presents substantial risks to federal systems. The KEV Catalog, established by Binding Operational Directive (BOD) 22-01, lists vulnerabilities posing significant risks to the federal enterprise. BOD 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies must fix these identified vulnerabilities by a set deadline. This directive aims to shield FCEB networks from current cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly recommends all organizations adopt similar practices. Prioritizing the remediation of vulnerabilities listed in the KEV Catalog is crucial for reducing cyberattack exposure. Organizations should integrate this prioritization into their regular vulnerability management processes. CISA will consistently update the KEV Catalog with new vulnerabilities that meet its established criteria.