Site icon TheCyberThrone

CISA Adds Five New Vulnerabilities to  KEV Catalog

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding five new vulnerabilities that pose a high risk to federal agencies and private enterprises. These newly listed vulnerabilities are being actively exploited by cybercriminals, making immediate patching and risk mitigation critical.

1. Breakdown of Newly Added KEV Vulnerabilities

🔴 Critical & Actively Exploited Security Flaws

1️⃣ CVE-2021-32030 – ASUS Router Authentication Bypass

2️⃣ CVE-2023-39780 – ASUS RT-AX55 OS Command Injection

3️⃣ CVE-2024-56145 – Craft CMS Code Injection

4️⃣ CVE-2025-3935 – ConnectWise ScreenConnect Authentication Bypass

5️⃣ CVE-2025-35939 – Craft CMS External Control of Web Parameters

2. Why These Vulnerabilities Are Urgent Concerns

Failure to patch these vulnerabilities may lead to ransomware infections, business disruptions, unauthorized data exposure, and potential regulatory fines for non-compliance with security policies.

3. Mitigation Strategies & Required Actions

✅ Immediate Security Patching

🔹 ASUS Routers – Apply firmware updates to secure authentication mechanisms and mitigate OS command injection risks.
🔹 Craft CMS – Deploy patches to address code injection vulnerabilities and web parameter manipulation flaws.
🔹 ConnectWise ScreenConnect – Implement security updates to strengthen authentication protocols and prevent unauthorized system access.

🔒 Strengthen System Protections

🔸 Enable Web Application Firewalls (WAFs) to filter malicious payload attempts.
🔸 Implement multi-factor authentication (MFA) for administrative and remote access accounts.
🔸 Deploy Intrusion Detection Systems (IDS) to monitor exploit attempts and suspicious activity.

⚠️ Federal Compliance Requirements

📌 Under Binding Operational Directive (BOD) 22-01, U.S. government agencies must remediate these vulnerabilities by the assigned deadline to remain compliant.
📌 Non-compliance may result in restricted access to federal systems, reputational damage, and heightened cybersecurity risks.

4. Conclusion & Next Steps

The addition of these five vulnerabilities to the KEV Catalog underscores their immediate danger, necessitating rapid response measures across affected sectors. Organizations must apply patches, enhance cybersecurity defenses, and monitor exploit attempts to prevent unauthorized intrusions.

Exit mobile version