CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-24054

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-73

CVE-2025-31201

Apple Multiple Products Arbitrary Read and Write Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31200

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-20035

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Vendor: SonicWall

Product: SMA100 Appliances

Added: 2025-04-16

Due Date: 2025-05-07

Description:

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2024-53150

Linux Kernel Out-of-Bounds Read Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-04-09

Due Date: 2025-04-30

Description:

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-125

CVE-2024-53197

Linux Kernel Out-of-Bounds Access Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-04-09

Due Date: 2025-04-30

Description:

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-29824

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-04-08

Due Date: 2025-04-29

Description:

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-30406

Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

Vendor: Gladinet

Product: CentreStack

Added: 2025-04-08

Due Date: 2025-04-29

Description:

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-321

CVE-2025-31161

Ransomware

CrushFTP Authentication Bypass Vulnerability

Vendor: CrushFTP

Product: CrushFTP

Added: 2025-04-07

Due Date: 2025-04-28

Description:

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-305

CVE-2025-22457

Ivanti Connect Secure, Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Vendor: Ivanti

Product: Connect Secure, Policy Secure and ZTA Gateways

Added: 2025-04-04

Due Date: 2025-04-11

Description:

Ivanti Connect Secure, Policy Secure and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below.

CWEs:

CWE-121

CVE-2025-24813

Apache Tomcat Path Equivalence Vulnerability

Vendor: Apache

Product: Tomcat

Added: 2025-04-01

Due Date: 2025-04-22

Description:

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-44 CWE-502

CVE-2024-20439

Cisco Smart Licensing Utility Static Credential Vulnerability

Vendor: Cisco

Product: Smart Licensing Utility

Added: 2025-03-31

Due Date: 2025-04-21

Description:

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-912

CVE-2025-2783

Google Chromium Mojo Sandbox Escape Vulnerability

Vendor: Google

Product: Chromium Mojo

Added: 2025-03-27

Due Date: 2025-04-17

Description:

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9875

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2019-9874

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502