logo

CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks

ID: cbb731a6-9158-51a7-b2b5-58350987f0d2

STIX ID: report--cbb731a6-9158-51a7-b2b5-58350987f0d2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-02-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog—most notably CVE-2024-45195, a critical (CVSS 9.8) Apache OFBiz RCE, and CVE-2024-29059, a .NET information disclosure—with proofs-of-concept and vendor fixes available; agencies and organizations are urged to apply patches or stop using affected products by February 25, 2025. The advisory includes two older Paessler PRTG flaws fixed in 2018, and while CISA marks the flaws as actively exploited, it provides no details about ongoing attacks or victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.