CISA Adds Three Known Exploite... Note

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including an Apple code execution vulnerability, an Apple cross-site scripting vulnerability, and an Oracle Agile Product Lifecycle Management incorrect authorization vulnerability. These vulnerabilities are frequently exploited by malicious actors and pose significant risks to the federal enterprise. The Known Exploited Vulnerabilities Catalog is a living list of CVEs that carry significant risk to the federal enterprise, and FCEB agencies are required to remediate identified vulnerabilities by the due date. CISA urges all organizations to prioritize timely remediation of catalog vulnerabilities as part of their vulnerability management practice. The agency will continue to add vulnerabilities to the catalog that meet specified criteria.