CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, which is based on evidence of active exploitation. The added vulnerability is CVE-2025-31161, a CrushFTP Authentication Bypass Vulnerability. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. The Known Exploited Vulnerabilities Catalog was established by Binding Operational Directive 22-01 to identify known Common Vulnerabilities and Exposures that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch agencies to remediate identified vulnerabilities by the due date to protect their networks against active threats. The directive only applies to FCEB agencies, but CISA urges all organizations to prioritize timely remediation of Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. The Known Exploited Vulnerabilities Catalog is a living list of known vulnerabilities that carry significant risk to the federal enterprise. CISA's goal is to reduce the risk of cyberattacks by prioritizing the remediation of these vulnerabilities. By remediating these vulnerabilities, organizations can protect themselves against active threats and reduce their exposure to cyberattacks.