CISA Adds Three Known Exploite... Note

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These include two Fortinet FortiSandbox OS command injection vulnerabilities and one Microsoft SharePoint deserialization vulnerability. These vulnerabilities are actively being exploited by cyber actors and present significant risks. The Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive emphasizes addressing high-risk vulnerabilities on publicly exposed assets that grant full control after exploitation. BOD 26-04 also sets expectations for agencies to check for compromises before applying patches. While BOD 26-04 specifically applies to federal agencies, CISA recommends all organizations adopt similar risk-based vulnerability management. CISA will continue to add vulnerabilities to the KEV Catalog as they are identified and exploited. Organizations can submit potential KEV additions to CISA if they have a CVE ID, evidence of exploitation, and mitigation guidance.