CISA Adds Four Urgent Vulnerabilities to KEV Catalog Amid Active Exploits

Published:

spot_img

Recent Cybersecurity Vulnerabilities Warning: CISA Updates Known Exploited Vulnerabilities Catalog

On July 8, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) took a significant step in cybersecurity by adding four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The inclusion of these flaws is essential as they have demonstrated active exploitation in various environments, raising alarms for organizations nationwide.

New Vulnerabilities Identified

The vulnerabilities listed are critical, some boasting a Common Vulnerability Scoring System (CVSS) score of up to 9.8, indicating they pose a severe risk if left unaddressed. Here’s a closer look at each:

CVE-2014-3931

  • CVSS Score: 9.8
  • Description: This buffer overflow vulnerability exists within the Multi-Router Looking Glass (MRLG). It may allow remote attackers to perform arbitrary memory writes, leading to significant memory corruption, making it a prime target for exploitation.

CVE-2016-10033

  • CVSS Score: 9.8
  • Description: Found in PHPMailer, this command injection vulnerability can enable attackers to execute arbitrary code within the application’s context. This may result in a denial-of-service (DoS) condition, crippling the affected service.

CVE-2019-5418

  • CVSS Score: 7.5
  • Description: This path traversal vulnerability is present in the Action View component of Ruby on Rails. By exploiting it, attackers can expose the contents of arbitrary files in the target system’s file structure, leading to potential data breaches.

CVE-2019-9621

  • CVSS Score: 7.5
  • Description: Associated with the Zimbra Collaboration Suite, this Server-Side Request Forgery (SSRF) vulnerability can lead to unauthorized access to internal resources, including remote code execution capabilities.

While there are currently no public reports indicating how the first three vulnerabilities are being actively exploited, the abuse of CVE-2019-9621 has been linked to a known actor. Trend Micro identified a group called Earth Lusca, associated with China, as the perpetrator involved in deploying web shells and utilizing Cobalt Strike.

Call to Action for Federal Agencies

To mitigate risks from these vulnerabilities, CISA strongly advises Federal Civilian Executive Branch (FCEB) agencies to apply the necessary software updates by July 28, 2025. Ensuring their networks remain secure is critical, especially in light of active exploitation.

Insights on Citrix Bleed 2 Vulnerability

In addition to the newly added vulnerabilities, CISA’s update coincides with revelations regarding a severe security flaw in Citrix NetScaler ADC, also referred to as Citrix Bleed 2 (CVE-2025-5777). Both watchTowr Labs and Horizon3.ai have released detailed analyses indicating this vulnerability is actively being exploited.

Technical Findings

Benjamin Harris, CEO of watchTowr, noted, "Active exploitation of both CVE-2025-5777 and CVE-2025-6543 is currently observed." This vulnerability enables attackers to read sensitive information processed in-memory, including critical data embedded in HTTP requests, credentials, and valid Citrix session tokens.

Horizon3.ai has determined that the weakness allows for data leakage, potentially enabling attackers to extract about 127 bytes of data through specially crafted HTTP requests. This could include session tokens or other sensitive information—an alarming prospect for organizations using Citrix solutions.

In technical discussions, it was mentioned that the issue stems from the usage of the snprintf function combined with a flawed format string. The format specifier pattern used indicates, "Print up to N characters or halt at the first null byte," creating an opportunity for attackers to incrementally leak sensitive data from uninitialized memory.

Understanding the Exploitation Process

WatchTowr elaborated on the exploitation mechanism, explaining that repeated access to the login authentication endpoint without a specific value could expose various sensitive data bits. "Every time you interact with the endpoint, more uninitialized stack data may be pulled into the response," the company emphasized. The systematic access to this endpoint could eventually yield valuable data for malicious actors.

Cybersecurity continues to be a pressing challenge for organizations globally, particularly as vulnerabilities like these become evident. Awareness and prompt action are essential to safeguarding sensitive data and protecting against the evolving threat landscape.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...