Site icon TheCyberThrone

CISA adds Craft CMS and PaloAlto Flaws to KEV Catalog

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) recently added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities are:

  1. CVE-2025-23209: A code injection vulnerability in Craft CMS.
  2. CVE-2025-0111: A file read vulnerability in Palo Alto Networks PAN-OS.

CISA sets March 13, 2025, as the deadline for federal agencies to remediate the vulnerabilities.

Detailed Analysis of CVE-2025-23209

Vulnerability Details

Exploitation

Mitigation Measures

Detailed Analysis of CVE-2025-0111

Vulnerability Details

Exploitation

Mitigation Measures

Conclusion

The addition of CVE-2025-23209 and CVE-2025-0111 to CISA’s KEV Catalog highlights the ongoing challenges in cybersecurity and the critical need for timely patching and remediation. Organizations are strongly encouraged to follow the recommended mitigation measures to protect their systems from these known exploited vulnerabilities.

Exit mobile version