CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. The vulnerabilities are CVE-2025-30406, a hard-coded cryptographic key issue in Gladinet CentreStack, and CVE-2025-29824, a use-after-free vulnerability in the Microsoft Windows Common Log File System Driver. These types of vulnerabilities are common attack vectors for malicious actors and pose significant risks to the federal enterprise. The Known Exploited Vulnerabilities Catalog was established by Binding Operational Directive 22-01 to identify and remediate significant risks to the federal enterprise. The directive requires Federal Civilian Executive Branch agencies to remediate identified vulnerabilities by the due date to protect their networks. The catalog is a living list of known Common Vulnerabilities and Exposures that carry significant risk to the federal enterprise. Although the directive only applies to FCEB agencies, CISA urges all organizations to prioritize timely remediation of catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet specified criteria. The agency encourages organizations to reduce their exposure to cyberattacks by prioritizing vulnerability remediation. By doing so, organizations can protect themselves against active threats and reduce the risk of cyberattacks.