CISA's list that day

10 January 2023

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Exchange Server and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-41080Privilege EscalationMicrosoft Exchange ServerPatch this weekRansomware use; EPSS 0.770.77
CVE-2023-21674Advanced Local Procedure Call (ALPC) Privilege EscalationMicrosoft WindowsPatch soon0.41

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.