logo

CISA Adds 5 New Vulnerabilities To KEV Catalog For 2025

ID: 4a8a1882-980f-5dd3-a3b3-8b5234e2adfc

STIX ID: report--4a8a1882-980f-5dd3-a3b3-8b5234e2adfc

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog affecting Advantive VeraCore (SQL injection CVE-2025-25181 and unrestricted file upload CVE-2024-57968) and Ivanti Endpoint Manager (three absolute path traversal vulnerabilities CVE-2024-13159/13160/13161). Several issues are rated critical (CVSS 9.8–9.9); CISA urges immediate patching, monitoring for suspicious activity, stricter access controls, and use of intrusion detection/prevention to mitigate exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.