Microsoft, Ivanti, and More: 2024 KEV Catalog Highlights Vendor Vulnerabilities
ID: b1dd04f7-ad08-5233-9f2a-449d3ae692dc
STIX ID: report--b1dd04f7-ad08-5233-9f2a-449d3ae692dc
Feed Name: The Cyber Express
Threat Score
In 2024 CISA expanded its Known Exploited Vulnerabilities (KEV) catalog by 185 entries (bringing the total to 1,238), documenting actively exploited flaws across many vendors — notably Microsoft and Ivanti — with common CWEs including OS command injection (CWE-78) and deserialization (CWE-502); the report stresses that both recent and long-standing vulnerabilities (including supply-chain–leveraged issues) remain actively exploited and pose broad operational risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
