Binding Operational Directive is a mandatory cyber risk management order that the U.S. Cybersecurity and Infrastructure Security Agency issues to federal civilian executive branch agencies, requiring specific security actions, deadlines, and reporting to address defined vulnerabilities and strengthen the security of federal information systems.
CISA has updated its Known Exploited Vulnerabilities Catalog with three new vulnerabilities under active exploitation, urging organizations to prioritize timely remediation to reduce cyberattack risks. The updates relate to vulnerabilities in WatchGuard Firebox, Gladinet Triofox, and Microsoft Windows.
CISA has added five vulnerabilities with evidence of active exploitation to its Known Exploited Vulnerabilities Catalog, urging federal agencies and organizations to prioritize remediation to reduce cyberattack exposure.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to the Known Exploited Vulnerabilities Catalog with a one-week remediation guideline.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This vulnerability is actively exploited, with a recommended remediation timeframe of one week. Federal agencies are required to address such vulnerabilities under BOD 22-01.
CISA added CVE-2025-21042, an out-of-bounds write flaw in Samsung mobile devices, to its Known Exploited Vulnerabilities catalog due to active exploitation.