What happened
The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities are actively exploited, indicating they are being used by malicious actors to compromise affected systems. The vulnerabilities include a heap-based buffer overflow in Fortinet products, an authentication bypass in Citrix NetScaler, an out-of-bounds write in Google Chromium V8, and an authentication bypass in Cisco Firewall Management Center. These flaws impact widely used enterprise products and are associated with severe risks related to asset control and data security. The vulnerabilities are classified as high severity due to ongoing exploitation and the critical nature of the affected components. The addition to the KEV Catalog underscores the importance for organisations to prioritise remediation efforts to close these security gaps swiftly.
Who is affected
Organisations running affected deployments of Fortinet multiple products, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center are impacted by these vulnerabilities. Due to the prevalence of these products in enterprise environments, a broad range of organisations could be exposed to the associated risks. The vulnerabilities affect systems that are reachable from the internet and could be exploited through specific attack vectors, risking control of affected assets and potential data breaches.
Recommended actions
- Verify whether affected products are exposed on publicly accessible networks.
- Implement rapid remediation strategies in accordance with organisational vulnerability management policies, prioritising the vulnerabilities listed in the KEV Catalog.
- Ensure active monitoring of affected systems for signs of compromise, especially for systems that may have been targeted for exploitation.
Indicators of compromise
Indicators are not currently available for these vulnerabilities.

