This content is restricted.
Brief
Summary:
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The catalog, established by Binding Operational Directive (BOD) 22-01, is a living list of known CVEs that pose significant risk to the federal enterprise. The added vulnerabilities include CVE-2020-3259, an information disclosure vulnerability in Cisco ASA and FTD, and CVE-2024-21410, a privilege escalation vulnerability in Microsoft Exchange Server. While BOD 22-01 only applies to Federal Civilian Executive Branch (FCEB) agencies, CISA urges all organizations to prioritize timely remediation of these vulnerabilities as part of their vulnerability management practice to reduce exposure to cyberattacks.
Highlights content goes here...
This content is restricted.
