The US Cybersecurity and Infrastructure Security Agency (CISA) has added 17 new vulnerabilities to its list of “Known Exploited Vulnerabilities Catalog.”

These vulnerabilities are actively being exploited in the wild, so the agency wants its offices under the Federal Civilian Executive Branch to guard against them by mitigating through patches or workarounds. 10 out of the 17 listed are needed to be secured by the first week of February, said CISA.

CISA’s Known Exploited Vulnerabilities Catalog

Periodically, the Cybersecurity and Infrastructure Security Agency (CISA) of the US publishes an updated ‘ Known Exploited Vulnerabilities Catalog ,’ where it lists security vulnerabilities that are actively being exploited at that time. And this week, the agency has added 17 new vulnerabilities to the list.

These, as per CISA, will allow threat actors to perform various attacks like remotely executing commands, stealing credentials and senstive information, gaining access to networks, and downloading and executing malware . As these are being abused in the wild, CISA wants its Federal Civilian Executive Branch (FCEB) agencies to act on them immediately.

10 among the total 17 new vulnerabilities added now are of high-risk nature. So CISA said these 10 notable vulnerabilities needed to be patched by the first week of February. In total, the 17 vulnerabilities added to the new Binding Operational Directive (BOD) 22-01 are;

CVE NumberCVE TitleRequired Action Due Date
CVE-2021-32648October CMS Improper Authentication2/1/2022
CVE-2021-21315System Information Library for node.js Command Injection Vulnerability2/1/2022
CVE-2021-21975Server Side Request Forgery in vRealize Operations Manager API Vulnerability2/1/2022
CVE-2021-22991BIG-IP Traffic Microkernel Buffer Overflow Vulnerability2/1/2022
CVE-2021-25296Nagios XI OS Command Injection Vulnerability2/1/2022
CVE-2021-25297Nagios XI OS Command Injection Vulnerability2/1/2022
CVE-2021-25298Nagios XI OS Command Injection Vulnerability2/1/2022
CVE-2021-33766Microsoft Exchange Server Information Disclosure Vulnerability2/1/2022
CVE-2021-40870Aviatrix Controller Unrestricted Upload of File Vulnerability2/1/2022
CVE-2021-35247SolarWinds Serv-U Improper Input Validation Vulnerability02/04/2022
CVE-2020-11978Apache Airflow Command Injection Vulnerability7/18/2022
CVE-2020-13671Drupal Core Unrestricted Upload of File Vulnerability7/18/2022
CVE-2020-13927Apache Airflow Experimental API Authentication Bypass Vulnerability7/18/2022
CVE-2020-14864Oracle Corporate Business Intelligence Enterprise Edition Path Traversal Vulnerability7/18/2022
CVE-2006-1547Apache Struts 1 ActionForm Denial of Service Vulnerability07/21/2022
CVE-2012-0391Apache Struts 2 Improper Input Validation Vulnerability07/21/2022
CVE-2018-8453Microsoft Windows Win32k Privilege Escalation Vulnerability07/21/2022

This disclosure aims to reduce the significant risk of known exploited vulnerabilities, says CISA. The updated list now has about 341 vulnerabilities in total.