CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has recently added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These include a vulnerability in Arista Extensible Operating System, another in Google Chromium's V8 engine, and a third in Cisco Catalyst SD-WAN Manager. Evidence confirms that these vulnerabilities are being actively exploited by malicious actors. Such vulnerabilities represent a common and significant threat to federal networks. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01 to track these high-risk vulnerabilities. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies must fix these identified vulnerabilities by their deadlines. The goal of BOD 22-01 is to safeguard FCEB networks from current cyber threats. While BOD 22-01 specifically applies to FCEB agencies, CISA strongly recommends all organizations take similar action. Prioritizing the remediation of KEV Catalog vulnerabilities is crucial for reducing overall cyberattack exposure. CISA will continue to update the KEV Catalog as new vulnerabilities meeting the criteria are identified.