CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2025-43300, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Apple iOS, iPadOS, and macOS and is an Out-of-Bounds Write vulnerability. Such vulnerabilities are commonly used by cyber attackers and present substantial risks to federal systems. CISA's Binding Operational Directive (BOD) 22-01 established the KEV Catalog to identify and address vulnerabilities with significant risk. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies fix these vulnerabilities by specified deadlines. The goal is to protect FCEB networks from ongoing cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly recommends all organizations adopt similar practices. Prioritizing the remediation of KEV Catalog vulnerabilities is crucial for enhancing cybersecurity defenses. CISA will consistently update the KEV Catalog with new vulnerabilities that meet the established criteria. This proactive approach aims to bolster the overall security posture against prevalent cyber threats.