CISA's list that day

16 November 2023

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Oracle Fusion Middleware, Sophos Web Appliance and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-2551UnspecifiedOracle Fusion MiddlewarePatch this weekEPSS 0.930.93
CVE-2023-1671Command InjectionSophos Web AppliancePatch this weekEPSS 0.990.99
CVE-2023-36584Mark of the Web (MOTW) Security Feature BypassMicrosoft WindowsPatch soon0.03

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.