CISA Adds Three Known Exploite... Note

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding three new vulnerabilities actively being exploited. These vulnerabilities include issues in Daemon Tools Lite, TanStack, and Nx Console. These vulnerabilities can be used by malicious actors and pose a considerable risk. The KEV Catalog is a list of known CVEs representing significant risks, created by Binding Operational Directive (BOD) 22-01. BOD 22-01 requires federal agencies to address KEVs by the due date to protect networks. CISA strongly recommends all organizations prioritize timely remediation of KEV vulnerabilities. This is essential for effective vulnerability management. The catalog serves as a dynamic resource, and CISA will make further additions as required. The updated catalog helps to safeguard against cyberattacks. Organizations must actively manage and remediate listed vulnerabilities.