Source URL: https://www.cisa.gov/news-events/alerts/2025/02/20/cisa-adds-two-known-exploited-vulnerabilities-catalog
Source: Alerts
Title: CISA Adds Two Known Exploited Vulnerabilities to Catalog
Feedly Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
CVE-2025-23209 Craft CMS Code Injection Vulnerability
CVE-2025-0111 Palo Alto Networks PAN-OS File Read Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
AI Summary and Description: Yes
Summary: The text discusses the recent addition of two new vulnerabilities to CISA’s Known Exploited Vulnerabilities Catalog, emphasizing their potential impact on security for federal agencies and the broader implications for vulnerability management practices across organizations. It highlights a proactive approach to cybersecurity through adherence to established directives.
Detailed Description:
– CISA (Cybersecurity and Infrastructure Security Agency) has updated its Known Exploited Vulnerabilities Catalog by adding two specific vulnerabilities, which indicates ongoing efforts to combat cybersecurity threats:
– **CVE-2025-23209**: Identified as a code injection vulnerability in Craft CMS.
– **CVE-2025-0111**: A file read vulnerability in Palo Alto Networks PAN-OS.
– **Significance of Vulnerabilities**:
– These vulnerabilities are recognized as frequent attack vectors for cybercriminals.
– They pose serious risks not only to federal agencies but also potentially to the private sector if exploited.
– **BOD 22-01 Overview**:
– Binding Operational Directive (BOD) 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies remediate identified vulnerabilities by a specified deadline.
– The directive seeks to minimize exposure to active threats, underscoring the importance of addressing vulnerabilities that could be exploited.
– **Importance of Timely Remediation**:
– CISA emphasizes that while BOD 22-01 specifically targets FCEB agencies, its recommendations are pertinent for all organizations seeking to strengthen their cybersecurity posture.
– Organizations are urged to prioritize vulnerabilities listed in the catalog as part of a comprehensive vulnerability management process.
– **Future Actions**:
– CISA commits to continually adding vulnerabilities to the catalog that meet specific criteria, ensuring that the cybersecurity landscape is addressed dynamically.
Key insights for professionals in security and compliance:
– The inclusion of vulnerabilities in the CISA catalog should prompt immediate action within organizations to evaluate their risk posture.
– Understanding the implications of BOD 22-01 can help organizations align their vulnerability management strategies with federal guidelines, even if they are not directly subject to them.
– The proactive stance encouraged by CISA underscores the necessity of maintaining up-to-date knowledge of vulnerabilities and enhancing overall cybersecurity resilience.