CISA’s KEV Catalog Update: Outdated Vulnerabilities Still Making Waves!
CISA’s Known Exploited Vulnerabilities catalog is getting crowded, featuring a .NET vulnerability CVE-2024-29059 that can lead to unauthenticated remote code execution. Despite patches and proof-of-concept exploits surfacing, public attack reports are as elusive as Bigfoot. Meanwhile, Microsoft plays coy, labeling the flaw as ‘exploitation more likely.’

Hot Take:
Looks like CISA’s to-do list is getting longer by the day! With vulnerabilities old and new popping up like whack-a-mole, it’s time for cybersecurity teams to channel their inner gamers and level up their defenses. Who knew patching could be such a retro hobby?
Key Points:
- CISA has added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a .NET flaw.
- The .NET vulnerability, CVE-2024-29059, was patched by Microsoft in January 2024.
- There are no public reports of attacks exploiting CVE-2024-29059, despite its addition to the KEV list.
- PRTG Network Monitor vulnerabilities from 2018 were also added, requiring admin privileges for exploitation.
- A remote code execution bug, CVE-2024-45195, in Apache OFBiz was further included, yet lacks public attack reports.
Already a member? Log in here