CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2024-32896 Android Pixel Privilege Escalation Vulnerability
CVE-2024-26169 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
CVE-2024-4358 Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See theÂBOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Feds say AI favors defenders over attackers in cyberspace — so farÂ

February 27, 2024 0 Comments 0 tags

As large language models and other artificial intelligence tools have proliferated more widely, researchers remain divided on whether highly capable AI tools will provide an advantage to attackers or defenders

Licensing AI Engineers

March 25, 2024 0 Comments 0 tags

The debate over professionalizing software engineers is decades old. (The basic idea is that, like lawyers and architects, there should be some professional licensing requirement for software engineers.) Here’s a

Treasury Sanctions Creators of 911 S5 Proxy Botnet

May 28, 2024 0 Comments 0 tags

The U.S. Department of the Treasury today unveiled sanctions against three Chinese nationals for allegedly operating 911 S5, an online anonymity service that for many years was the easiest and