CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-48384

Git Link Following Vulnerability

Vendor: Git

Product: Git

Added: 2025-08-25

Due Date: 2025-09-15

Description:

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-59 CWE-436

CVE-2024-8068

Citrix Session Recording Improper Privilege Management Vulnerability

Vendor: Citrix

Product: Session Recording

Added: 2025-08-25

Due Date: 2025-09-15

Description:

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-269

CVE-2024-8069

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Vendor: Citrix

Product: Session Recording

Added: 2025-08-25

Due Date: 2025-09-15

Description:

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-43300

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2025-08-21

Due Date: 2025-09-11

Description:

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-54948

Trend Micro Apex One OS Command Injection Vulnerability

Vendor: Trend Micro

Product: Apex One

Added: 2025-08-18

Due Date: 2025-09-08

Description:

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-8876

N-able N-Central Command Injection Vulnerability

Vendor: N-able

Product: N-Central

Added: 2025-08-13

Due Date: 2025-08-20

Description:

N-able N-Central contains a command injection vulnerability via improper sanitization of user input.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8875

N-able N-Central Insecure Deserialization Vulnerability

Vendor: N-able

Product: N-Central

Added: 2025-08-13

Due Date: 2025-08-20

Description:

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

Vendor: RARLAB

Product: WinRAR

Added: 2025-08-12

Due Date: 2025-09-02

Description:

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-35

CVE-2007-0671

Microsoft Office Excel Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893

Microsoft Internet Explorer Resource Management Errors Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-399

CVE-2020-25078

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2022-40799

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

Vendor: D-Link

Product: DNR-322L

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-494

CVE-2023-2533

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

Vendor: PaperCut

Product: NG/MF

Added: 2025-07-28

Due Date: 2025-08-18

Description:

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-352

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74