CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a new vulnerability, CVE-2024-21182, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Oracle WebLogic Server and has been observed being actively exploited by malicious actors. Such vulnerabilities represent frequent attack vectors that pose significant risks to federal systems. CISA's Binding Operational Directive (BOD) 22-01 established the KEV Catalog to identify vulnerabilities with substantial risk to the federal enterprise. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these identified vulnerabilities by a specified deadline. The goal of BOD 22-01 is to protect FCEB networks against ongoing cyber threats. While BOD 22-01 specifically applies to FCEB agencies, CISA strongly recommends that all organizations adopt similar practices. Prioritizing the timely remediation of KEV Catalog vulnerabilities is crucial for reducing overall cyberattack exposure. Organizations should integrate this into their regular vulnerability management processes. CISA will consistently update the KEV Catalog with new vulnerabilities that meet its established criteria.