CISA has added three critical vulnerabilities to the List of Known Exploitable Vulnerabilities (KEV) and is warning organizations to apply security updates immediately.

The three vulnerabilities affect various popular systems and software, posing significant risks to both organizations and individual users.
Let's take a closer look at the vulnerabilities in the CISA KEV List:
CVE-2017-1000253: Linux Kernel Vulnerability
The first vulnerability affects the Linux Kernel. A local attacker could exploit this vulnerability to gain elevated privileges on vulnerable systems, gaining unauthorized access to sensitive resources.
This vulnerability has already been used in ransomware.
Organizations using Linux systems should immediately apply the necessary security updates or discontinue use if no workarounds are available.
See also: LiteSpeed Cache Vulnerability: 6 million WordPress sites at risk
CVE-2024-40766: Vulnerability in SonicWall SonicOS
The second vulnerability affects SonicWall SonicOS, a widely used operating system for firewalls.
This is an access control vulnerability that could allow unauthorized access to system resources and, under certain circumstances, cause the firewall to crash.
And this vulnerability appears to have been used in ransomware.
CVE-2016-3714: Vulnerability in ImageMagick software
The third vulnerability added to CISA's KEV List affects ImageMagick , a popular software suite used for image editing and conversion .
This vulnerability is related to "improper input validation", affecting EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN PLT coders.
See also: LoadMaster vulnerability allows hackers to execute arbitrary code
A remote attacker could exploit the vulnerability in ImageMagick by using shell metacharacters in a crafted image, potentially executing arbitrary code on the affected system.
CISA recommends implementing vendor-provided protections or discontinuing use of ImageMagick if no mitigations are available.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CISA orders federal agencies to implement appropriate protection measures (updates and other solutions provided by vendors) by September 30.
CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
See also: Veeam fixes vulnerabilities in Backup & Replication (VBR)
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: gbhackers.com
