logo

Microsoft, Ivanti, and More: 2024 KEV Catalog Highlights Vendor Vulnerabilities

ID: b1dd04f7-ad08-5233-9f2a-449d3ae692dc

STIX ID: report--b1dd04f7-ad08-5233-9f2a-449d3ae692dc

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2024-12-30

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

In 2024 CISA expanded its Known Exploited Vulnerabilities (KEV) catalog by 185 entries (bringing the total to 1,238), documenting actively exploited flaws across many vendors — notably Microsoft and Ivanti — with common CWEs including OS command injection (CWE-78) and deserialization (CWE-502); the report stresses that both recent and long-standing vulnerabilities (including supply-chain–leveraged issues) remain actively exploited and pose broad operational risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.