CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog
- CVE-2025-21418 (7.8 high) Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
- CVE-2025-21391 (7.1 high) Microsoft Windows Storage Link Following Vulnerability
- CVE-2024-40890 (8.8 high) Zyxel DSL CPE OS Command Injection Vulnerability
- CVE-2024-40891 (8.8 high) Zyxel DSL CPE OS Command Injection Vulnerability
The Zyxel stuff is not new, but since the Microsoft zero-days are part of #PatchTuesday, I'm including them in this conversation.
#cisa #kev #cisakev #KnownExploitedVulnerabilitiesCatalog #vulnerability #zeroday #eitw #activeexploitation #infosec #cybersecurity #cve