CISA Alert: Two New Cyber Threats Added to Exploited Vulnerabilities Catalog!

CISA has added two new vulnerabilities, CVE-2025-54236 and CVE-2025-59287, to its Known Exploited Vulnerabilities Catalog. These vulnerabilities are popular with cybercriminals, posing significant risks to federal systems. The KEV Catalog guides agencies in tackling such threats, ensuring they patch up their digital fortresses before being virtually egged.

Pro Dashboard

Hot Take:

**_It’s like CISA’s KEV Catalog is the ultimate “Who’s Who” of vulnerabilities. With Adobe and Microsoft taking the spotlight, it’s a wonder they haven’t started charging admission to this catastrophic concert of cyber chaos!_**

Key Points:

– CISA has added two new vulnerabilities to the KEV Catalog: one affecting Adobe Commerce and Magento, and another impacting Microsoft Windows Server Update Service.
– The vulnerabilities are CVE-2025-54236 and CVE-2025-59287, respectively.
– These vulnerabilities are prime targets for cyber attackers, posing a significant threat to federal systems.
– The KEV Catalog is maintained to help federal agencies prioritize and remediate high-risk vulnerabilities.
– Federal agencies are required to address these vulnerabilities by designated deadlines under BOD 22-01.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?