CISA Adds CVE-2025-24472 And CVE-2025-30066 To KEV Catalog
ID: 8adc94c4-bacf-5e01-8c87-e43db79815ed
STIX ID: report--8adc94c4-bacf-5e01-8c87-e43db79815ed
Feed Name: Cyble Blog
CISA added two high-severity, actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an authentication-bypass in Fortinet FortiOS/FortiProxy (CVE-2025-24472) enabling remote escalation to super-admin, and a supply-chain malicious-code vulnerability in the tj-actions/changed-files GitHub Action (CVE-2025-30066) that allowed theft of secrets. Both carry high CVSS scores and CISA/GitHub/Fortinet have released fixes; organizations are advised to patch immediately, rotate exposed credentials, and harden workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
