CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities include CVE-2024-8069 and CVE-2024-8068, both related to Citrix Session Recording, and CVE-2025-48384 concerning Git link following. Evidence indicates these vulnerabilities are being actively exploited by malicious actors. Such vulnerabilities represent frequent attack vectors and pose significant risks to federal networks. CISA's Binding Operational Directive (BOD) 22-01 established the KEV Catalog to address these risks. This directive mandates Federal Civilian Executive Branch (FCEB) agencies to remediate listed vulnerabilities by a specific deadline. The goal is to protect FCEB networks from active cyber threats. Although BOD 22-01 specifically targets FCEB agencies, CISA strongly recommends all organizations prioritize these vulnerabilities. Timely remediation is crucial for reducing exposure to cyberattacks. CISA will continue to update the KEV Catalog with vulnerabilities meeting its criteria.