logo

CISA Adds WhatsUp Gold, MSHTML Vulnerabilities List

ID: 7cf0636f-211b-51bb-a93e-8fd9faa2585d

STIX ID: report--7cf0636f-211b-51bb-a93e-8fd9faa2585d

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

Cyble warns that CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2024-6670 (Progress WhatsUp Gold, critical 9.8, exploited quickly after PoC with observed RCE and 381 internet-exposed instances) and CVE-2024-43461 (MSHTML UI-spoofing used in a chained exploit); organizations are urged to apply vendor patches, check for IOCs, and follow recommended mitigation best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.