The Cybersecurity and Infrastructure Security Agency (CISA) added 41 vulnerabilities to its list of known exploitable flaws in the past two days, including flaws for the Android kernel and Cisco IOS XR.
See also: CISA to federal agencies: Fix vulnerable VMware products or remove them from your network

The additional vulnerabilities come from a wide range of years, with the oldest disclosed being from 2016 and the most recent being a Cisco IOS XR vulnerability that was patched last Friday.
See also: CISA: 7 New Security Flaws Vulnerable to Attacks
The Cisco IOS XR vulnerability, tracked as CVE-2022-20821, allows attackers to write arbitrary files to the containerized file system, retrieve Redis database information, or write to the Redis database in memory.
Other interesting flaws are two Android Linux Kernel flaws tracked as CVE-2021-1048 and CVE-2021-0920. While both of these flaws are found in the Linux, they are only known to be used in limited attacks against Android devices.
Regarding CVE-2021-1048, Google's Threat Analysis Team (TAG) recently reported that it was used with other zero-days in an attack chain that installed the Predator spyware .
CISA has given federal agencies until June 13, 2022, to implement security updates for the Android and Cisco.

Other vulnerabilities
The remaining thirty-eight flaws added to CISA's list all have a known active exploit status, so the organization is simply including them as part of its regular additions.
The flaws affect Cisco, Microsoft , Apple , Google , Mozilla , Facebook , Adobe , and Webkit GTK software products , ranging from 2018 to 2021.
Included is a Windows elevation of privilege vulnerability tracked as CVE-2020-0638 that was disclosed in 2020 but was found to still be used by the Conti ransomware in attacks on corporate networks.
As threat actors continue to use older vulnerabilities in attacks, administrators must install updates on all devices, including older versions that may still be running in corporate environments.
See also: CISA: Attackers exploit flaw in Windows Print Spooler
CISA requires federal agencies to fix all flaws added on Monday by June 13, 2022, while the other 20 added today must be fixed by June 14, 2022.
To see the current list of exploited vulnerabilities, you can view CISA's List of Known Exploited Vulnerabilities, which can be downloaded in various offline formats.
Information source: bleepingcomputer.com
