CISA's list that day
10 October 2023
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Cisco IOS and IOS XE, Adobe Acrobat and Reader, Microsoft WordPad and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-21608Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.61 | 0.61 | ||
| CVE-2023-41763Privilege Escalation | Microsoft Skype for Business | Patch this weekEPSS 0.90 | 0.90 | ||
| CVE-2023-44487Rapid Reset Attack | IETF HTTP/2 | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2023-36563Information Disclosure | Microsoft WordPad | Patch soon | 0.21 | ||
| CVE-2023-20109Group Encrypted Transport VPN Out-of-Bounds Write | Cisco IOS and IOS XE | Patch soon | 0.02 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.