CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to their active exploitation. These include a Cisco Secure Firewall vulnerability, a Microsoft Windows WinSock vulnerability, and a Metabase SQL injection vulnerability. Such vulnerabilities are common attack methods for cybercriminals and present significant dangers to federal networks. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize fixing vulnerabilities listed in the KEV Catalog. This directive specifically targets publicly exposed assets granting full control post-exploitation. Agencies are also required to assess systems for compromise before applying patches. Although BOD 26-04 is specific to FCEB agencies, CISA urges all organizations to use a risk-based approach for managing vulnerabilities. CISA will continue to add vulnerabilities to the KEV Catalog that meet the stated conditions. Organizations can nominate exploited vulnerabilities not yet in the catalog via CISA’s KEV Nomination Form. Submissions require a CVE ID, proof of exploitation, and clear guidance on mitigation.