CISA Ask Federal Agencies To Patch 66 New Flaws Exploited By Attackers

U.S. Cybersecurity and Infrastructure Security Agency (CISA) has uncovered 66 new vulnerabilities that are exploited by attackers.

The agency urged federal agencies to apply available patches before April 15, 2022, to limit the risk of the bugs being exploited.

Based on evidence of active exploitation, the 66 bugs include current and older bugs in networking kit, several Windows bugs, and security appliances from D-Link, Cisco, Netgear, Citrix, Kuiper, Palo Alto, Sophos, Zyxel, and enterprise software from Oracle, OpenBSD, VMware, and others.

Some of the vulnerabilities identified vulnerabilities include a flaw affecting Watch Guard’s Firefox and XTM appliances (CVE-2022-26318), and another flaw impacting Mitel’s MiCollab, MiVoice Business Express Access Control Vulnerability (CVE-2022-26143).

Hackers exploited the Mitel bug to launch the TP240PhoneHome DDoS attack. A Windows Print Spooler Elevation of Privilege vulnerability, traced as CVE-2022-21999, has also been added to the list of bugs to be patched.

For more information read the original story in ZDNet.

Top Stories

Related Articles

May 31, 2025 In response to escalating concerns over U.S. government influence on cloud operations, Microsoft has committed to legally contesting more...

May 31, 2025 A new opinion piece in the New York Times warns that the U.S. Department of Government Efficiency (DOGE), more...

April 22, 2025 The United States has long been a magnet for global STEM talent, fueling its dominance in technology and more...

April 10, 2025 The US Office of the Comptroller of the Currency (OCC) reported a cybersecurity breach involving unauthorized access to more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.