Site icon TheCyberThrone

CISA adds CISCO ISE and PaperCut MF flaws to KEV Catalog

Advertisements

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 28, 2025, following evidence of active exploitation. These include two vulnerabilities affecting Cisco Identity Services Engine (ISE) and one affecting the PaperCut NG/MF print management software.

Details on Newly Added Vulnerabilities

1. CVE-2025-20281 – Cisco ISE Injection Vulnerability

2. CVE-2025-20337 – Cisco ISE Injection Vulnerability

3. PaperCut NG/MF (CVE-2023-2533) – Cross-Site Request Forgery (CSRF) & Remote Code Execution

CISA KEV Catalog & Action Items

CISA’s KEV catalog highlights vulnerabilities that pose severe risks due to active exploitation. Federal Civilian Executive Branch (FCEB) agencies are required by Binding Operational Directive 22-01 to patch these by August 18, 2025. All other organizations—including those in private sectors—are strongly urged to patch immediately to reduce exposure and risk.

Recommended Steps

Failure to remediate exposes organizations to ransomware, data theft, and additional systemic risks.

Exit mobile version