CISA Flags Actively Exploited Flaws in AMI, D-Link, and Fortinet Devices
ID: 66e4fb19-7e3d-56b4-9ae0-f47b45d03fae
STIX ID: report--66e4fb19-7e3d-56b4-9ae0-f47b45d03fae
Feed Name: Halcyon Blog
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog — a CVSS 10.0 remote authentication bypass in AMI MegaRAC (CVE-2024-54085), a D-Link DIR-859 path traversal (CVE-2024-0769) affecting end-of-life routers, and a Fortinet hard-coded crypto key issue (CVE-2019-6693) reportedly leveraged by Akira ransomware; federal agencies must implement mitigations by July 16, 2025, and the report stresses that inadequate asset and patch management are primary drivers enabling these compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
