CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These are CVE-2013-3893 affecting Microsoft Internet Explorer, CVE-2007-0671 impacting Microsoft Office Excel, and CVE-2025-8088 related to RARLAB WinRAR. These vulnerabilities are frequently used by malicious actors and present substantial risks. The KEV Catalog was established by Binding Operational Directive 22-01 to identify vulnerabilities with significant risk. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these identified vulnerabilities. The goal is to protect FCEB networks from active cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly recommends that all organizations address these vulnerabilities. Prioritizing their remediation is crucial for reducing exposure to cyberattacks. Organizations should integrate KEV Catalog vulnerability remediation into their regular vulnerability management practices. CISA will continue to update the catalog with new vulnerabilities meeting specific criteria.