CISA | Alerts
Follow
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities have been confirmed as being actively exploited by malicious actors. The newly added vulnerabilities include issues in Mozilla products, Microsoft Internet Explorer and Windows, the Linux Kernel, and Oracle E-Business Suite. Such frequently exploited vulnerabilities represent a significant risk to federal networks. Binding Operational Directive 22-01 mandates that Federal Civilian Executive Branch agencies remediate these identified vulnerabilities. This directive aims to protect FCEB networks against current cyber threats. While BOD 22-01 specifically targets federal agencies, CISA strongly advises all organizations to address KEV Catalog vulnerabilities. Prioritizing the remediation of these known exploited issues is crucial for reducing an organization's cyberattack exposure. CISA will continue to update the KEV Catalog with new vulnerabilities that meet its criteria. This ongoing process ensures organizations are informed about and can address critical cyber risks.