The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added eight more vulnerabilities to its list of bugs known to be used in cyberattacks. The vulnerabilities include a mix of old and new bugs.
See also: Critical vulnerability in WordPress plugin affects thousands of sites

CISA publishes these vulnerabilities to raise awareness of cybersecurity risks and to remind federal agencies of their obligation to promptly apply security updates to stay protected.
As we mentioned above, the 8 new additions to the list include vulnerabilities that are already being used in attacks. This means that they pose a significant risk to organizations and businesses, as they allow for the compromise of mobile devices, access to networks, the ability to execute commands remotely, etc.
See also: Bug: MacBook battery drains when in sleep mode
You can see the 8 vulnerabilities in the table below:
| CVE ID | Description | Patch Deadline |
| CVE-2022-22587 | Apple IOMobileFrameBuffer Memory Corruption Vulnerability | 2/11/2022 |
| CVE-2021-20038 | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | 2/11/2022 |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 7/28/2022 |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 7/28/2022 |
| CVE-2020-0787 | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | 7/28/2022 |
| CVE-2014-1776 | Microsoft Internet Explorer Use-After-Free Vulnerability | 7/28/2022 |
| CVE-2020-5722 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | 7/28/2022 |
| CVE-2017-5689 | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | 7/28/2022 |
The most recent vulnerability, known as CVE-2022-22587, was discovered in 2022 and is a memory corruption bug in IOMobileFrameBuffer that affects iOS, iPadOS, and macOS “Monterey.” Apple released a security update to fix the zero-day last Wednesday. Due to the potential impact of this vulnerability on many devices, CISA has given federal agencies until February 11, 2022, to implement security updates.
CISA also added the vulnerability CVE-2021-20038 affecting SonicWall SMA 100 Appliances. Researchers discovered that cybercriminals were actively scanning and attempting to exploit this vulnerability. As a result, CISA is also requiring agencies to patch this bug by February 11, 2022.
See also: FBI: Warns of cyberattack on Beijing Olympics
As for the older flaws, CVE-2013-6271 is considered particularly critical. This vulnerability, along with other bugs, was used in old campaigns and large-scale DNS hijacking attacks.
With the addition of these eight bugs to CISA ’s Known Exploited Vulnerabilities, there are now a total of 351 vulnerabilities being used in attacks.
Source: Bleeping Computer
