CISA Adds Two Known Exploited ... Note

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, CVE-2025-8875 and CVE-2025-8876, affect N-able N-central and involve insecure deserialization and command injection respectively. Such vulnerabilities are common tools for cybercriminals and present considerable dangers to federal systems. Binding Operational Directive (BOD) 22-01 established the KEV Catalog to identify vulnerabilities posing significant risks. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies fix these vulnerabilities by a set deadline. This is to safeguard FCEB networks from current cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA recommends all organizations address KEV Catalog vulnerabilities. Prioritizing these remediations is crucial for improving overall cybersecurity. CISA will continue to update the catalog with newly identified exploited vulnerabilities. Organizations should integrate KEV remediation into their regular vulnerability management processes.