CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has added five newly discovered vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, all showing evidence of active exploitation in the wild. The vulnerabilities affect products from Hikvision, Rockwell, and Apple, ranging from authentication bypass to use-after-free flaws. Federal agencies are required to remediate these vulnerabilities by established deadlines under BOD 22-01, with CISA urging all organizations to prioritize patching these actively exploited flaws.
Summary
CISA has added five newly discovered vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, all showing evidence of active exploitation in the wild. The vulnerabilities affect products from Hikvision, Rockwell, and Apple, ranging from authentication bypass to use-after-free flaws. Federal agencies are required to remediate these vulnerabilities by established deadlines under BOD 22-01, with CISA urging all organizations to prioritize patching these actively exploited flaws.
Indicators of Compromise
- cve — CVE-2017-7921
- cve — CVE-2021-22681
- cve — CVE-2021-30952
- cve — CVE-2023-41974
- cve — CVE-2023-43000