CISA Adds Three Known Exploite... Note

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These newly identified vulnerabilities include a Linux Kernel Time-of-Check Time-of-Use race condition, an unspecified vulnerability in the Android Runtime, and a deserialization vulnerability in multiple Sitecore products. These types of vulnerabilities are frequently used by malicious actors to launch cyberattacks and present substantial risks to government entities. The KEV Catalog was established by Binding Operational Directive 22-01, which mandates that Federal Civilian Executive Branch agencies address these known exploited vulnerabilities. This directive aims to protect FCEB networks from ongoing cyber threats by requiring timely remediation. While BOD 22-01 specifically targets federal agencies, CISA strongly encourages all organizations to prioritize fixing these KEV Catalog vulnerabilities. This proactive approach is crucial for reducing an organization's susceptibility to cyberattacks. By treating KEV vulnerabilities as a priority within their vulnerability management, organizations can enhance their security posture. CISA will continue to update the KEV Catalog with new vulnerabilities that meet its established criteria.