CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2024-8963 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See theÂBOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

EPA ‘urgently’ needs to step up cybersecurity assistance for the water sector, GAO says

August 1, 2024 0 Comments 0 tags

The Environmental Protection Agency is falling far behind on some of the basic duties that come with its responsibilities as the federal lead for helping the water and wastewater sector

#Infosec2024: What to Expect at Infosecurity Europe 2024

May 28, 2024 0 Comments 0 tags

Get ready for Infosecurity Europe 2024 with these top five picks from Infosecurity Magazine to help you plan your visit

Understanding NullBulge, the New AI-Fighting ‘Hacktivist’ Group

July 17, 2024 0 Comments 0 tags

The threat actor who claimed the recent Disney hack previously targeted AI-centric games and applications with commodity malware and ransomware