CISA Adds Five Actively Exploited Vulnerabilities To KEV Catalog
ID: 573ebcd6-70e5-5bb4-9a3c-9e6e4eeb83b1
STIX ID: report--573ebcd6-70e5-5bb4-9a3c-9e6e4eeb83b1
Feed Name: Cyble Blog
CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog affecting Oracle E-Business Suite (SSRF), Microsoft Windows SMB Client (improper access control leading to privilege escalation), two Kentico Xperience CMS authentication-bypass flaws, and an Apple JavaScriptCore arbitrary code execution issue. The advisory notes active exploitation or elevated risk, directs federal agencies to remediate by Nov 10, 2025, and provides mitigation and hardening recommendations (patching, restricting SMB, retiring EoL Apple devices, monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
