CISA's list that day

24 April 2024

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in CrushFTP and Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD). US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-4040VFS Sandbox EscapeCrushFTP CrushFTPPatch this weekMetasploit module; EPSS 0.990.99
CVE-2024-20353ASA and FTD Denial of ServiceCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Patch this weekEPSS 0.710.71
CVE-2024-20359ASA and FTD Privilege EscalationCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Patch soon0.19

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.