By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Seven Exploited Vulnerabilities to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday the addition of seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities have been actively targeted by malicious actors, indicating their significant risk to organizations. The inclusion in the KEV catalog mandates that federal agencies patch these vulnerabilities by a specific deadline, typically within weeks, to mitigate potential cyber threats. The agency's directive underscores the urgency with which these newly identified exploitable weaknesses must be addressed across government networks.
The seven vulnerabilities now listed include CVE-2026-83548, a critical server-side request forgery (SSRF) flaw in SonicWall SMA 1000 Appliances. This vulnerability, assigned a perfect CVSS score of 10.0, allows remote, unauthenticated attackers to execute arbitrary code. Attackers have been observed deploying reverse shells and cryptocurrency miners through this exploit, highlighting its severe impact. Another significant addition is CVE-2024-21348, a remote code execution vulnerability in Microsoft Windows. This flaw, with a CVSS score of 8.8, enables attackers to gain control of vulnerable systems. Microsoft has provided security updates to address this issue, urging users to apply them promptly.
Further vulnerabilities added to the KEV catalog include CVE-2024-20666, a critical authentication bypass vulnerability in VMware vCenter Server, which carries a CVSS score of 9.8. This flaw could allow unauthenticated attackers to gain administrative access to affected vCenter Server instances. Additionally, CVE-2023-38545, a critical vulnerability in the GNU C Library (Glibc), has been identified. This flaw, rated with a CVSS score of 9.8, can lead to a heap-based buffer overflow, potentially resulting in denial-of-service or arbitrary code execution. The exploitation of Glibc vulnerabilities is particularly concerning due to its widespread use across numerous Linux distributions and applications.
CISA also added CVE-2023-32246, a critical vulnerability in the Linux kernel, which has a CVSS score of 9.8. This flaw could allow a local attacker to gain root privileges. The catalog also features CVE-2023-29337, a critical remote code execution vulnerability in Microsoft SharePoint Server, with a CVSS score of 9.8, and CVE-2023-35191, a critical remote code execution vulnerability in the NetScaler ADC and NetScaler Gateway, also rated at 9.8. The inclusion of these high-severity vulnerabilities emphasizes the ongoing threat landscape and the need for continuous vigilance and rapid patching by organizations to protect their critical infrastructure and sensitive data from sophisticated cyberattacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.