惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
量子位
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
V
Visual Studio Blog
雷峰网
雷峰网
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
有赞技术团队
有赞技术团队
博客园 - 叶小钗
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog

Cyberwarzone

LinkedIn Sued Over Browser Extension Scanning Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage
CISA adds five actively exploited vulnerabilities to KEV ...
2026-03-16 · via Cyberwarzone

Peter Chofield Avatar

Peter Chofield

·

1–2 minutes

CISA on March 5 added five vulnerabilities affecting Advantive VeraCore, Ivanti Endpoint Manager, Microsoft .NET Framework, and D-Link DIR-859 routers to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild. The agency said the additions were made under Binding Operational Directive 22-01, which requires Federal Civilian Executive Branch agencies to remediate listed flaws by specified deadlines.

According to CISA’s alert, the newly added vulnerabilities are CVE-2024-57968 and CVE-2025-25181 in Advantive VeraCore, CVE-2025-22467 in Ivanti Endpoint Manager, CVE-2025-24043 in Microsoft .NET Framework, and CVE-2024-0769 in D-Link DIR-859 routers. CISA described the VeraCore issues as unrestricted file upload and OS command injection bugs, the Ivanti issue as an absolute path traversal flaw, the Microsoft bug as an information disclosure vulnerability, and the D-Link issue as an operating system command injection vulnerability.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.” — CISA alert, March 5, 2026

CISA set a remediation due date of March 26, 2026 for CVE-2024-57968, CVE-2025-25181, CVE-2025-22467, and CVE-2025-24043. The agency gave federal agencies until May 21, 2026 to remediate CVE-2024-0769 in D-Link DIR-859 routers.

Five exploited flaws affect enterprise software and edge hardware

The two VeraCore vulnerabilities affect warehouse management and fulfillment software used in supply-chain environments, while the Ivanti Endpoint Manager flaw impacts enterprise systems management deployments. The Microsoft .NET Framework issue broadens the KEV update beyond edge and appliance software, and the D-Link DIR-859 entry shows that internet-facing router weaknesses continue to make the catalog when exploitation is observed.

CISA’s bulletin does not provide exploitation details, indicators of compromise, or victim counts for the five additions. The agency instead directs defenders to the KEV catalog entry for each CVE and reiterates that all organizations should prioritize timely remediation of vulnerabilities listed as actively exploited.

The batch KEV update extends a pattern Cyberwarzone has already tracked in recent CISA activity, including the n8n remote code execution flaw that CISA added to the KEV catalog after active exploitation and broader coverage of high-impact vendor security updates affecting enterprise environments.

About the Author

Peter Chofield Avatar

Peter Chofield

Passionate about cybersecurity, Peter dedicates his days to reading, analyzing, and writing about the trends shaping the online world.