CISA's list that day
5 October 2023
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Atlassian Confluence Data Center and Server, Progress WS_FTP Server and Apple iOS and iPadOS. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-22515Broken Access Control | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2023-40044Deserialization of Untrusted Data | Progress WS_FTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| CVE-2023-42824Kernel Privilege Escalation | Apple iOS and iPadOS | Patch soon | 0.01 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.