The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild. These vulnerabilities impact Microsoft SharePoint Server (CVE-2024-38094), WSO2 API Manager (CVE-2022-29464), and Adobe Commerce/Magento (CVE-2024-34102).
Exploitation of these flaws can result in Remote Code Execution (RCE), allowing attackers to gain unauthorized access and take full control of affected systems. Organizations and federal agencies are required to apply vendor-provided patches within specific deadlines to mitigate the risk of data breaches and further network intrusion.
Top comments (0)