The US Cybersecurity and Infrastructure Security Agency (CISA) has added 95 vulnerabilities to its list of actively exploited security issues – a truly large number.

See also: CISA: List of free cybersecurity tools and services released
Despite the fact that some of them have been known for almost two decades, the agency notes that the bugs "pose significant risk to organizations.".
Critical bugs recently added to the list
Under BOD 22-01 on mitigating the risk of known exploitable vulnerabilities, federal agencies are given just over three weeks to patch the 95 vulnerabilities recently added to the CISA list, with the deadline for most of them being March 24th.
See also: CISA: Federal agencies must fix Chrome and Magento bugs
For 27 of the vulnerabilities, there is a shorter deadline for patching, March 17, largely because they are more recent and affect systems that provide access to sensitive information or allow movement to devices on the network. Eight of these bugs have a high critical severity rating (at least 9.8).

The most recent entries in CISA's list of known exploitable vulnerabilities affect products primarily from Microsoft (Windows, Office) and Cisco.
However, there are products from other vendors or projects – Oracle, Adobe, Mozilla, Siemens, Apache, Exim, Linux, Treck TCP/IP stack and ChakraCore.
Ancient flaws still exist
Surprisingly, it appears that federal agencies are still running systems with Adobe Flash Player, even though support for the product ended on the last day of 2020.
Adobe in early 2021 also blocked Flash content from running in Flash Player, and the company “recommends all users to uninstall it immediately” due to inherent security risks.
Some of the Flash Player bugs identified by CISA have a critical severity rating of 9.8 out of 10 and are over five years old (e.g. CVE-2016-4117 and CVE-2016-1019).
The oldest vulnerability on the list is from 2002, however, a privilege escalation vulnerability tracked as CVE-2002-0367 that affects the smss.exe debugging subsystem in Windows NT and Windows 2000.
See also: CISA and FBI: Data wiping attacks will also appear outside Ukraine
The following list lists the oldest 10 vulnerabilities that CISA added to the List of Known Exploitable Vulnerabilities:
- CVE-2011-0611
- CVE-2010-3333
- CVE-2010-0232
- CVE-2010-0188
- CVE-2009-3129
- CVE-2009-1123
- CVE-2008-3431
- CVE-2008-2992
- CVE-2004-0210
- CVE-2002-0367
Applying security updates when they become available should be a priority for both public and private sector organizations.
The US cybersecurity agency encourages all entities to fix all security issues added to its list to reduce their exposure to cyberattacks.
Information source: bleepingcomputer.com
