HomeSecurityCISA added Sudo vulnerability to KEV List

CISA added Sudo vulnerability to KEV List

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Sudo tool for Linux and Unix operating systemsto its list of Known Exploitable Vulnerabilities (KEV). This means that the agency has evidence of active exploitation of the vulnerability.

CISA vulnerability Sudo KEV Catalog

The vulnerability is tracked as CVE-2025-32463 (CVSS score: 9.3) and affects versions of Sudo prior to 1.9.17p1. It was discovered by Stratascale researcher Rich Mirchin July 2025.

See also: Security flaws in Tile allow location tracking

“Sudo contains a vulnerability that could allow a local attacker to exploit sudo's -R (–chroot) option to execute arbitrary commands as root, even if they are not listed in the sudoers file.“.

It is currently unknown how this vulnerability is exploited in actual attacks and who may be behind such attempts.

However, the inclusion of Sudo in the KEV List highlights that the risk is not theoretical but practical — organizations must react as if an exploit is already active. The existence of active exploit modules accelerates the need for immediate upgrades and control of sudoers policies on production systems.

At the same time, major distributions have already received patches and guidance, so the critical step for administrators is to: (a) install 1.9.17p1 or later, (b) audit chroot usage, and (c) control local account access — measures that significantly reduce the risk of successful escalation.

See also: WhatsApp: Vulnerability exploited via malicious DNG file

CISA added Sudo vulnerability to KEV List

CISA: What other vulnerabilities did you add to the List?

Also, four other security vulnerabilities were added to the KEV list:

  • CVE-2021-21311 – Adminer contains a server-side request forgery that, when exploited, could allow a remote attacker to obtain potentially sensitive information. (Disclosed by Google Mandiant in May 2022 and used by a threat actor called UNC2903, targeting AWS IMDS configurations)
  • CVE-2025-20352 – Cisco IOS and IOS XE contain a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow denial of service or remote code execution. (Disclosed by Cisco last week)
  • CVE-2025-10035 – Fortra GoAnywhere MFT contains a “deserialization of untrusted data” vulnerability, which could allow command injection attacks. (Disclosed by watchTowr Labs last week)
  • CVE-2025-59689 – Libraesva Email Security Gateway (ESG) contains a command injection vulnerability that allows commands to be injected via a compressed email attachment. (Disclosed by Libraesva last week)

See also: Vulnerabilities in SUSE Rancher allow Administrator Account blocking

In light of the active exploitation, federal FCEB services, relying on the affected products, are advised to implement the necessary protection actions by October 20, 2025, to secure their networks.

CISA added Sudo vulnerability to KEV List
CISA added Sudo vulnerability to KEV List

CISA KEV Catalog

CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization (in terms of fixing security gaps).

Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.

See also: Formbricks: Vulnerability allows password reset without authorization

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications. Overall, CISA's role is vital to protecting the digital infrastructure of the United States and other regions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS