logo

CISA warns of actively exploited bugs in Chrome and Excel parsing library

ID: e121db15-cb7a-58d1-9fb4-05cf73b3a676

STIX ID: report--e121db15-cb7a-58d1-9fb4-05cf73b3a676

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-01-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-7101, an RCE in the Perl Spreadsheet::ParseExcel library exploited in the wild (used against Barracuda ESG appliances by UNC4841 to deploy SeaSpy and Saltwater), and CVE-2023-7024, a Chrome WebRTC heap overflow zero-day fixed via emergency updates; vendors have provided patches and CISA issued mitigation guidance and deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.