CISA added six vulnerabilities affecting products from Apple, Adobe, Apache, D-Link and Joomla to the list of “ Known Exploited Vulnerabilities ” (KEV)

The KEV list contains security issues that are known to have been actively used in attacks. It can greatly assist organizations around the world in properly managing vulnerabilities and prioritizing security.
See also: AI Engine: Vulnerability in WordPress plugin puts 50,000 sites at risk
According to CISA, these vulnerabilities are frequently used by cybercriminals to carry out attacks and pose significant risks to federal business.
The agency gave federal agencies a deadline of January 29 to fix vulnerabilities in Apple, Adobe, Apache, D-Link and Joomla products. Otherwise, they will have to stop using the vulnerable products.
See also: Microsoft Patch Tuesday January 2024: Fixes 49 vulnerabilities
The six vulnerabilities added to the CISA list are as follows:
CVE-2023-38203 (vulnerability severity rating 9.8/10): Found in Adobe ColdFusion 2018U17 and earlier, 2021U7 and earlier, and 2023U1 and earlier, leading to arbitrary code execution without user interaction.
CVE-2016-20017 (vulnerability severity rating 9.8 /10): Allows unauthorized command injection and is detected in D-Link DSL-2750B devices before version 1.05.
CVE-2023-29300 (vulnerability severity rating 9.8/10): Detected in Adobe ColdFusion 2018U16 and earlier, 2021U6 and earlier, and 2023.0.0.330468 and earlier, leading to arbitrary code execution without user.
CVE-2023-41990 (vulnerability severity rating 7.8/10): Allows remote code execution when processing a font file sent as an iMessage, leading to arbitrary code execution on iPhone devices running iOS 16.2 and earlier.
CVE-2023-27524 (vulnerability severity rating 8.9/10): This vulnerability affects Apache Superset versions up to 2.0.1. The vulnerability exists when the default SECRET_KEY is not changed, allowing an attacker to gain access to unauthorized resources.
CVE-2023-23752 (vulnerability severity rating 5.3/10): Affects Joomla! versions 4.0.0 to 4.2.7 and allows unauthorized access to web service endpoints.
Although some vulnerabilities have been used by cybercriminals for years, attacks have only recently become known. For example, CVE-2023-41990 was used in the “Operation Triangulation” campaign that was active since 2019 and was discovered in June 2023 by Kaspersky.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
See also: CISA warns of vulnerabilities in Chrome and Excel

Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
It provides information and tools to help organizations protect their networks from cyberattacks and deal with any attacks that may occur.
In addition, it informs the public about any vulnerabilities in widely used systems and applications. Overall, CISA's role is vital to protecting the digital infrastructure of the United States and other regions.
Source: www.bleepingcomputer.com
