logo

CISA Expands Known Exploited Vulnerabilities Catalog with Four Critical Issues

ID: d7709f64-419d-507f-b421-de16a74aafbd

STIX ID: report--d7709f64-419d-507f-b421-de16a74aafbd

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2025-03-05

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: a Linux kernel uninitialized buffer memory-leak (CVE-2024-50302) and three VMware issues — an ESXi arbitrary kernel write (CVE-2025-22225, CVSS 8.2), a TOCTOU race enabling code execution (CVE-2025-22224, CVSS 9.3), and an out-of-bounds read information disclosure (CVE-2025-22226, CVSS 7.1). Organizations using affected Linux and VMware products are urged to prioritize patching, apply vendor guidance, and implement compensating controls to mitigate active exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.