CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2024-20481 Cisco ASA and FTD Denial-of-Service Vulnerability
CVE-2024-37383 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See theBOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

National Records of Scotland Data Breached in NHS Cyber-Attack

May 23, 2024 0 Comments 0 tags

National Records of Scotland said sensitive personal data it holds was part of information stolen and published online by ransomware attackers from NHS Dumfries and Galloway

Trump campaign says emails were hacked, jumpstarting ‘a wild ride’ to election day

August 11, 2024 0 Comments 0 tags

LAS VEGAS — The apparent hack-and-leak operation targeting former President Donald Trump’s presidential campaign portends a potential “wild” election season, a former top U.S. cybersecurity official said Sunday. Rob Joyce, the

White House wants to boost cyber funds for fiscal 2026

July 11, 2024 0 Comments 0 tags

The White House wants federal agencies to ask for more money that would be used to improve the nation’s cyber defenses, per a memo sent to agency heads Wednesday. In