CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a new vulnerability, CVE-2025-10585, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Google Chromium's V8 engine and is characterized as a type confusion vulnerability. Such vulnerabilities are commonly exploited by malicious actors and present substantial risks to federal systems. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01 to list vulnerabilities with significant federal enterprise risk. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies fix these identified vulnerabilities by a specified deadline. The goal is to safeguard FCEB networks from active cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly encourages all organizations to adopt similar practices. Prioritizing the remediation of KEV Catalog vulnerabilities is recommended for all entities to minimize cyberattack risks. This proactive approach should be integrated into their routine vulnerability management processes. CISA will continue to update the KEV Catalog with new vulnerabilities that meet the established criteria.