CISA Adds Seven Known Exploite... Note

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA updated its Known Exploited Vulnerabilities (KEV) Catalog with seven newly identified security flaws. These vulnerabilities, affecting products like Microsoft Windows, Adobe Acrobat, Microsoft Exchange Server, and Fortinet, are actively being exploited by malicious actors. The addition is based on evidence indicating that these vulnerabilities are frequent attack vectors. BOD 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies must remediate vulnerabilities listed in the KEV Catalog by specified deadlines. This directive helps safeguard FCEB networks from existing cyber threats. The KEV Catalog serves as a dynamic list of CVEs that pose substantial risks. While BOD 22-01 is binding for FCEB agencies, CISA recommends all organizations to prioritize patching these vulnerabilities. Timely remediation of KEV Catalog vulnerabilities is crucial for effective vulnerability management. CISA will continue to expand the catalog with new vulnerabilities that meet their established criteria.