TL;DR

['CISA has added CVE-2025-31125, CVE-2025-34026, CVE-2025-54313, and CVE-2025-68645 to its KEV catalog due to evidence of active exploitation.']

What happened

['CISA has incorporated four new vulnerabilities into the Known Exploited Vulnerabilities Catalog based on evidence of current exploitation. These include improper access control in Vite, improper authentication in Versa Concerto, embedded malicious code in Prettier eslint-config-prettier, and PHP remote file inclusion in Zimbra Collaboration Suite.']

Why it matters for ops

["These vulnerabilities are common entry points for cyberattacks and pose a significant risk to federal enterprises. CISA's Binding Operational Directive 22-01 mandates FCEB agencies to remediate these identified risks by the due date."]

Mitigation

  • Implement updates and patches to address known vulnerabilities. Follow CISA's KEV catalog recommendations for remediation timelines.

Action items

  • Review the KEV catalog for any listed vulnerabilities relevant to your systems. Prioritize patching or mitigation actions based on severity

Detection IOCs

  • CVE-2025-31125
  • CVE-2025-34026
  • CVE-2025-54313
  • CVE-2025-68645

Source link

https://www.cisa.gov/news-events/alerts/2026/01/22/cisa-adds-four-known-exploited-vulnerabilities-catalog