The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security vulnerabilities, affecting Citrix Session Recording and Git, to its list of Known Exploitable Vulnerabilities (KEVs). This means that the vulnerabilities are already being used by cybercriminals for attacks.

Let's take a brief look at the three vulnerabilities:
- CVE -2024-8068 (CVSS score: 5.1/10) concerns improper privilege handling in Citrix Session Recording. It could allow escalation of privileges to access the NetworkService Accountwhen an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain.
- The vulnerability CVE-2024-8069 (CVSS score: 5.1/10) concerns the deserialization of untrusted data in Citrix Session Recording and allows limited remote code execution with the privileges of a NetworkService Account access, when an attacker is an authenticated user on the same intranet as the session recording server.
- CVE-2025-48384 (CVSS score: 8.1/10) is a link following vulnerability in Git that results from inconsistent handling of carriage return (CR) characters in configuration files. This could ultimately lead to code execution.
Both Citrix vulnerabilities were patched by the company in November 2024 after a responsible disclosure by watchTowr Labs on July 14, 2024. In contrast, CVE-2025-48384 in Git was addressed in July 2025. A proof-of-concept (PoC) exploit was released by Datadog after the public disclosure.
See also: Tableau Server: Critical vulnerability allows system compromise

“ If a submodule path contains a trailing CR, the corrupted path can cause Git to initialize the submodule in an unexpected location ,” Arctic Wolf reported for CVE-2025-48384. “ When combined with a symlink pointing to the submodule hooks directory and an executable post-checkout hook, cloning a repository can lead to unexpected code execution .”
CISA: Citrix and Git vulnerabilities in the KEV Catalog
The inclusion of new vulnerabilities in the KEV list is an indication that these weaknesses are not theoretical, but are already being exploited by attackers in real-world organizations. This increases the criticality of addressing them early, especially in environments where Citrix Session Recording is used extensively for session monitoring and logging or Git for software development. Citrix vulnerabilities pose a particular risk to organizations with large internal networks, as they allow authenticated users to escalate privileges and move laterally in the network. This can be a starting point for insider threat attacks, especially when access controls are not sufficiently strict.
See also: vtenext CRM: Multiple vulnerabilities allow RCE attacks
On the other hand, the vulnerability in Git is worrisome because it concerns a platform that is a key link in software supply chains. A repository can serve as a gateway for introducing malicious code into critical projects, potentially affecting hundreds of downstream users or organizations. The fact that a PoC is available makes the risk immediate, as it facilitates the rapid adaptation of exploits by malicious actors.

As is typical, CISA has not provided further technical details about the Citrix and Git exploit activity. It has also not said who may be behind the attacks.
Federal agencies are required to implement the necessary remediation actions by September 15, 2025 to secure their networks against active threats.
See also: Apple vulnerability: PoC Exploit released for zero-day bug
CISA’s deadline for federal agencies underscores the seriousness of the situation. However, private organizations should also act quickly: install security patches, implement continuous monitoring for suspicious activity, and adopt secure code review practices. Rapid response is the only way to reduce the window of opportunity for exploitation of these active threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
