CISA's list that day

10 October 2023

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Cisco IOS and IOS XE, Adobe Acrobat and Reader, Microsoft WordPad and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-21608Use-After-FreeAdobe Acrobat and ReaderPatch this weekEPSS 0.610.61
CVE-2023-41763Privilege EscalationMicrosoft Skype for BusinessPatch this weekEPSS 0.900.90
CVE-2023-44487Rapid Reset AttackIETF HTTP/2Patch this weekEPSS 0.990.99
CVE-2023-36563Information DisclosureMicrosoft WordPadPatch soon0.21
CVE-2023-20109Group Encrypted Transport VPN Out-of-Bounds WriteCisco IOS and IOS XEPatch soon0.02

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.