• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    DPDP and Cybersecurity

    DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete

    AI-Powered Bots

    AI-Powered Bots Are Blurring the Line Between Users and Cyber Threats

    Software Supply Chain Attack, Supply Chain Attack, Mini Shai-Hulud, NCSC, CI/CD

    The NHS Was Lucky. The Next Victim Might Not Be.

    META Threat Landscape Report

    Ransomware and Geopolitical Tensions Drive Cyber Threats Across META in Q1 2026

    Qilin

    Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

    CVE-2025-48595

    Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks

    Miasma

    Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

    CVE-2026-41089

    Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

    ChatGPhish

    New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    Crypto Scam, Crypto

    New Threat Actor Targets Crypto Firms’ Development Infrastructure

    Pink, Pink Extortion, CL-CRI-1147

    Pink Extortion Group Emerges Targeting Microsoft 365 Data

    AI-Powered Bots

    AI-Powered Bots Are Blurring the Line Between Users and Cyber Threats

    AI-Native Cybersecurity

    Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    DPDP and Cybersecurity

    DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete

    AI-Powered Bots

    AI-Powered Bots Are Blurring the Line Between Users and Cyber Threats

    Software Supply Chain Attack, Supply Chain Attack, Mini Shai-Hulud, NCSC, CI/CD

    The NHS Was Lucky. The Next Victim Might Not Be.

    META Threat Landscape Report

    Ransomware and Geopolitical Tensions Drive Cyber Threats Across META in Q1 2026

    Qilin

    Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

    CVE-2025-48595

    Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks

    Miasma

    Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

    CVE-2026-41089

    Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

    ChatGPhish

    New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    Crypto Scam, Crypto

    New Threat Actor Targets Crypto Firms’ Development Infrastructure

    Pink, Pink Extortion, CL-CRI-1147

    Pink Extortion Group Emerges Targeting Microsoft 365 Data

    AI-Powered Bots

    AI-Powered Bots Are Blurring the Line Between Users and Cyber Threats

    AI-Native Cybersecurity

    Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cyber News

5 New Vulnerabilities Added to CISA’s Known Exploited List: Urgent Action Required

Samiksha Jain by Samiksha Jain
September 19, 2024
in Cyber News, Firewall Daily, Vulnerability News
0
Vulnerabilities

Source: Freepik

774
SHARES
4.3k
VIEWS
Share on LinkedInShare on Twitter

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog, highlighting the continued threat that these security gaps pose to organizations worldwide. These vulnerabilities have been flagged due to active exploitation, making them critical targets for cybercriminals seeking to infiltrate and damage federal and private-sector systems alike.

The vulnerabilities are identified as CVE-2024-27348 (Apache HugeGraph-Server Improper Access Control Vulnerability), CVE-2020-0618 (Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability), CVE-2019-1069 (Microsoft Windows Task Scheduler Privilege Escalation Vulnerability), CVE-2022-21445 (Oracle JDeveloper Remote Code Execution Vulnerability), and CVE-2020-14644 (Oracle WebLogic Server Remote Code Execution Vulnerability).

All five present significant risks and are actively being targeted by malicious actors, according to CISA’s evidence of exploitation.

CISA’s Known Exploited Vulnerabilities Catalog, which is updated regularly, highlights Common Vulnerabilities and Exposures (CVEs) that pose an immediate risk to organizations and their IT infrastructure. Each newly identified vulnerability, if left unaddressed, could lead to severe consequences such as unauthorized access, privilege escalation, and even remote code execution, potentially crippling networks, leaking sensitive information, or causing widespread operational disruptions.

Breaking Down New Vulnerabilities

1. CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability

Apache HugeGraph-Server, a graph database management system, suffers from an improper access control vulnerability that could allow remote attackers to execute arbitrary code on an affected server. The flaw stems from insufficient restrictions on access control mechanisms, opening a path for attackers to exploit the system remotely.

Action Required: Organizations using Apache HugeGraph-Server should immediately apply the vendor-provided mitigations to patch this vulnerability. If no patch is available, discontinuing the use of this product is advised to avoid potential compromise.

report-ad-banner

2. CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

This vulnerability affects Microsoft SQL Server Reporting Services, where a deserialization flaw allows an authenticated attacker to execute arbitrary code on the server. By improperly handling page requests, the service becomes vulnerable to remote code execution, placing the server’s data and functionality at risk.

Action Required: Microsoft has issued guidance on how to mitigate this vulnerability. Organizations must promptly apply these mitigations to secure their systems. If mitigation isn’t feasible, discontinuing use is the recommended course of action to protect the network from exploitation.

3. CVE-2019-1069: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows Task Scheduler, a core system utility, contains a flaw in the SetJobFileSecurityByName() function, which could enable a local, authenticated attacker to gain elevated SYSTEM privileges. This elevation could provide the attacker with full control over the affected system, allowing for far-reaching malicious activities.

Action Required: Organizations should implement Microsoft’s recommended patches or security updates. Failure to address this issue could leave the system open to severe privilege escalation, allowing attackers to execute commands with SYSTEM-level privileges.

4. CVE-2022-21445: Oracle JDeveloper Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Oracle JDeveloper, a popular development tool within Oracle’s Fusion Middleware suite. The vulnerability lies within the ADF Faces component, which suffers from deserialization flaws. These weaknesses can be exploited remotely, potentially allowing attackers to execute malicious code without the need for authentication.

Action Required: Oracle users should follow the recommended steps provided in Oracle’s advisory to mitigate this vulnerability. If mitigations are unavailable or ineffective, organizations should consider discontinuing the use of Oracle JDeveloper to prevent remote exploitation.

5. CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

Another critical vulnerability identified in Oracle’s Fusion Middleware suite affects the WebLogic Server. This remote code execution vulnerability allows attackers to exploit deserialization weaknesses, enabling unauthenticated remote access via T3 or IIOP protocols. This can lead to the compromise of the entire server.

Action Required: Oracle has issued a patch for this vulnerability. Immediate application of this patch is essential for ensuring system security. As with the other vulnerabilities, if no patch or workaround is available, discontinuing the use of the product is strongly recommended to avoid an attack.

A Call to Action for Federal Agencies and Beyond

The addition of these vulnerabilities to the Known Exploited Vulnerabilities Catalog comes under CISA’s Binding Operational Directive (BOD) 22-01, which mandates that Federal Civilian Executive Branch (FCEB) agencies address and remediate these vulnerabilities by a set due date. This is part of an ongoing effort to protect federal networks from active cyber threats.

Although BOD 22-01 specifically applies to FCEB agencies, CISA urges all organizations—both public and private—to adopt the same level of diligence. With the increasing sophistication of cyberattacks, organizations cannot afford to leave these vulnerabilities unpatched. Implementing timely remediation and incorporating vulnerability management practices are vital steps to protecting networks from exploitation.

Understanding the Broader Impact of These Vulnerabilities

Vulnerabilities like the ones listed above are often the most popular entry points for cybercriminals. Whether it’s through improper access controls, privilege escalation, or remote code execution, these security flaws present significant risks to any organization handling sensitive data or operating complex systems.

If exploited, such vulnerabilities can result in:

  • Data breaches: Leading to the exposure of sensitive or personal information.
  • Operational disruptions: As attackers could seize control of servers, halt services, or demand ransoms.
  • Reputational damage: Companies that fall victim to cyberattacks often suffer long-term damage to their reputation and customer trust.
  • Legal and financial consequences: Non-compliance with security standards, such as failing to address known vulnerabilities, could result in heavy fines and legal action.

The continued addition of vulnerabilities to CISA’s Known Exploited Vulnerabilities Catalog is a reminder of the importance of proactive cybersecurity measures. Organizations must prioritize remediation and keep their systems updated to prevent these threats from wreaking havoc on their networks.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CISACISA's Known Exploited Vulnerabilities CatalogThe Cyber ExpressThe Cyber Express NewsVulnerabilities
Previous Post

10 Critical Indicators Your Company is Vulnerable to Cyberattacks

Next Post

U.S. Taxpayer Data at Risk? LockBit Ransomware Claims Attack on IRS-Authorized eFile

Next Post
eFile LockBit ransomware

U.S. Taxpayer Data at Risk? LockBit Ransomware Claims Attack on IRS-Authorized eFile

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

DPDP and Cybersecurity
Features

DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete

June 5, 2026
VerdantBamboo
Cyber News

China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

June 5, 2026
Fraud, Agentic AI, AI-assisted Cyberattacks
Cyber News

Study of AI-Assisted Cyberattacks May Reshape How Security Industry Measures Risk

June 5, 2026
Crypto Scam, Crypto
Cyber News

New Threat Actor Targets Crypto Firms’ Development Infrastructure

June 4, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information