CYBERSECURITYTRACKER
TRACKING7,665 stories in this site build1,646 vulnerability news stories in this site build
Permanent story citation

CISA Adds Three Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4260

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: a Cisco firewall heap inspection flaw, a Microsoft Windows use-after-free issue, and a Metabase SQL injection bug. The agency reinforced that federal agencies must prioritize patching KEV-listed vulnerabilities on publicly exposed systems and investigate potential compromise before patch application, per Binding Operational Directive 26-04. CISA encourages all organizations to adopt risk-based vulnerability management aligned with KEV prioritization.

Why it matters: Federal agencies and enterprises must urgently patch these three vulnerabilities on internet-facing assets; practitioners should check the KEV Catalog for all three CVEs and initiate remediation while investigating logs for evidence of prior compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: a Cisco firewall heap inspection flaw, a Microsoft Windows use-after-free issue, and a Metabase SQL injection bug. The agency reinforced that federal agencies must prioritize patching KEV-listed vulnerabilities on publicly exposed systems and investigate potential compromise before patch application, per Binding Operational Directive 26-04. CISA encourages all organizations to adopt risk-based vulnerability management aligned with KEV prioritization.

Why it matters: Federal agencies and enterprises must urgently patch these three vulnerabilities on internet-facing assets; practitioners should check the KEV Catalog for all three CVEs and initiate remediation while investigating logs for evidence of prior compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: a Cisco firewall heap inspection flaw, a Microsoft Windows use-after-free issue, and a Metabase SQL injection bug. The agency reinforced that federal agencies must prioritize patching KEV-listed vulnerabilities on publicly exposed systems and investigate potential compromise before patch application, per Binding Operational Directive 26-04. CISA encourages all organizations to adopt risk-based vulnerability management aligned with KEV prioritization.

Why it matters: Federal agencies and enterprises must urgently patch these three vulnerabilities on internet-facing assets; practitioners should check the KEV Catalog for all three CVEs and initiate remediation while investigating logs for evidence of prior compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary