CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These are CVE-2020-24363 affecting TP-Link TL-WA855RE and CVE-2025-55177 affecting Meta Platforms WhatsApp. The inclusion indicates that these vulnerabilities are actively being exploited by malicious actors. Such vulnerabilities represent significant risks, particularly to the federal enterprise. Binding Operational Directive 22-01 established the KEV Catalog to address these risks. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities. The goal is to protect FCEB networks from active threats. While BOD 22-01 specifically targets FCEB agencies, CISA encourages all organizations to prioritize these remediations. This proactive approach helps reduce exposure to cyberattacks. CISA will continue to update the catalog with vulnerabilities meeting its criteria.