CISA adds 41 vulnerabilities to catalog of exploited bugs
Organizations are required to fix the flaws by June 13 and 14 to “reduce their exposure to cyber attacks”
The Cybersecurity and Infrastructure Security Agency (CISA) added 41 vulnerabilities to its catalog of known exploited bugs this week.
The batch is one of the largest to be added to the list since the organization began compiling it back in November last year, with the additions including bugs relating to the likes of Microsoft, Apple, Google, Cisco, Adobe, Facebook, WhatsApp, Mozilla, Kaseya, Artifex, and QNAP.
The dates of these vulnerabilities range from 2016 to 2021, with the CISA giving federal agencies until June 13 and 14 to provide patches and “reduce their exposure to cyber attacks".
The organisation says it adds exploited vulnerabilities “when they become known”. subject to an executive review and when they satisfy three key thresholds: the vulnerability has an assigned Common Vulnerabilities and Exposures (CVE) ID, there is reliable evidence that it has been actively exploited in the wild, and when there is clear remediation action for the bug.
The oldest of the batch dates back to 2016 and concerns a Microsoft Internet Explorer Disclosure Vulnerability titled CVE-2016-0162, used to allow remote attackers to determine the existence of files via crafted JavaScript code.
The most recent listing is a Cisco IOS XR open port vulnerability (CVE-2022-20821), which was fixed last week. This bug is used to allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container.
Elsewhere, two Android Linux Kernel flaws were also added - CVE-2021-1048 and CVE-2021-0920 – which have been known to only be used in limited attacks against Android devices.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
CISA also listed the Windows elevation of privileges vulnerability (CVE-2020-0638). Despite being disclosed back in 2020, the flaw was still being used by ransomware gang Conti as part of corporate attacks this year.
The list of vulnerabilities were added to the catalog in two parts, with CISA giving federal agencies until June 13th for the 21 added on Monday, and until June 14th for the 20 listed on Tuesday.
Dan is a freelance writer and regular contributor to ChannelPro, covering the latest news stories across the IT, technology, and channel landscapes. Topics regularly cover cloud technologies, cyber security, software and operating system guides, and the latest mergers and acquisitions.
A journalism graduate from Leeds Beckett University, he combines a passion for the written word with a keen interest in the latest technology and its influence in an increasingly connected world.
He started writing for ChannelPro back in 2016, focusing on a mixture of news and technology guides, before becoming a regular contributor to ITPro. Elsewhere, he has previously written news and features across a range of other topics, including sport, music, and general news.
-
How small businesses can maximize productivity with Dell Pro laptops – even without an IT teamSponsored Dell Pro 5 and Pro 3 laptops can help a small business embrace productivity growth, hybrid working, and AI, all in a secure fashion without the need for a dedicated IT department
-
Nvidia CEO Jensen Huang hails 'excellent' Chinese AI modelsNews As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals