logo

CISA warns of critical Oracle, Mitel flaws exploited in attacks

ID: abceb0a1-bb0f-5863-888d-66189f9a1570

STIX ID: report--abceb0a1-bb0f-5863-888d-66189f9a1570

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-07

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a critical unauthenticated path traversal in Mitel MiCollab (CVE-2024-41713) that can allow unauthorized administrative actions and access to user/network information, a second authenticated MiCollab path traversal (CVE-2024-55550) with limited impact, and a critical Oracle WebLogic flaw (CVE-2020-2883) historically patched but reported as actively exploited; federal agencies are required to remediate these within the BOD 22-01 timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.