New Cyber Nightmares: ARM and PHP Vulnerabilities Added to CISA’s Exploited List

CISA has added two new vulnerabilities, including the ARM Mali GPU Kernel Driver Use-After-Free Vulnerability, to its Known Exploited Vulnerabilities Catalog. These are frequent attack vectors posing significant risks to the federal enterprise.

Hot Take:

Looks like CISA’s Known Exploited Vulnerabilities Catalog just got two new unwanted guests! It’s like a VIP list, but for cyberattacks. Forget red carpets, these vulnerabilities bring drama right to your doorstep—if your doorstep is a federal network.

Key Points:

  • Two new vulnerabilities added to CISA’s Known Exploited Vulnerabilities Catalog.
  • CVE-2024-4610 targets ARM Mali GPU Kernel Driver with a Use-After-Free vulnerability.
  • CVE-2024-4577 affects PHP-CGI with an OS Command Injection vulnerability.
  • Binding Operational Directive (BOD) 22-01 mandates FCEB agencies to address these vulnerabilities.
  • CISA recommends all organizations to prioritize timely remediation of cataloged vulnerabilities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here