Brief

Summary:

The Cybersecurity and Infrastructure Security Agency (CISA) has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog, comprising of vulnerabilities in Adobe ColdFusion, Apache Superset, Apple, D-Link, and Joomla!. These vulnerabilities are considered high-risk and are being actively exploited by malicious actors. The CISA urges all organizations, not just Federal Civilian Executive Branch (FCEB) agencies, to prioritize the remediation of these vulnerabilities to reduce the risk of cyberattacks.

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

  • CVE-2023-38203 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
  • CVE-2023-29300 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
  • CVE-2023-27524 Apache Superset Insecure Default Initialization of Resource Vulnerability
  • CVE-2023-41990 Apple Multiple Products Code Execution Vulnerability
  • CVE-2016-20017 D-Link DSL-2750B Devices Command Injection Vulnerability
  • CVE-2023-23752 Joomla! Improper Access Control Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Highlights content goes here...

Summary:

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities Catalog, adding six new vulnerabilities that have been exploited in the wild. The catalog, established by Binding Operational Directive (BOD) 22-01, is a living list of common vulnerabilities and exposures (CVEs) that pose significant risks to the federal enterprise.

The new additions to the catalog are:

1. CVE-2023-38203: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
2. CVE-2023-29300: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
3. CVE-2023-27524: Apache Superset Insecure Default Initialization of Resource Vulnerability
4. CVE-2023-41990: Apple Multiple Products Code Execution Vulnerability
5. CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability
6. CVE-2023-23752: Joomla! Improper Access Control Vulnerability

These vulnerabilities are frequently used as attack vectors by malicious cyber actors, and their exploitation poses significant risks to federal agencies and other organizations. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect their networks against active threats.

While BOD 22-01 only applies to FCEB agencies, CISA strongly encourages all organizations to prioritize the timely remediation of vulnerabilities listed in the catalog as part of their vulnerability management practice. This is essential for reducing the risk of cyberattacks and protecting sensitive information.

CISA will continue to update the catalog with new vulnerabilities that meet specified criteria, providing organizations with essential information to stay ahead of emerging threats. By prioritizing vulnerability remediation and staying informed about known exploited vulnerabilities, organizations can significantly reduce their exposure to cyberattacks and ensure the security of their networks and data.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies