CISA's list that day

5 October 2023

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Atlassian Confluence Data Center and Server, Progress WS_FTP Server and Apple iOS and iPadOS. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-22515Broken Access ControlAtlassian Confluence Data Center and ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2023-40044Deserialization of Untrusted DataProgress WS_FTP ServerPatch this weekRansomware use; Metasploit module; EPSS 0.900.90
CVE-2023-42824Kernel Privilege EscalationApple iOS and iPadOSPatch soon0.01

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.