logo

CISA Adds CVE-2025-24472 And CVE-2025-30066 To KEV Catalog

ID: 8adc94c4-bacf-5e01-8c87-e43db79815ed

STIX ID: report--8adc94c4-bacf-5e01-8c87-e43db79815ed

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

CISA added two high-severity, actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an authentication-bypass in Fortinet FortiOS/FortiProxy (CVE-2025-24472) enabling remote escalation to super-admin, and a supply-chain malicious-code vulnerability in the tj-actions/changed-files GitHub Action (CVE-2025-30066) that allowed theft of secrets. Both carry high CVSS scores and CISA/GitHub/Fortinet have released fixes; organizations are advised to patch immediately, rotate exposed credentials, and harden workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.