CISA's list that day

9 October 2024

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Ivanti Cloud Services Appliance (CSA) and Fortinet Multiple Products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-9380OS Command InjectionIvanti Cloud Services Appliance (CSA)Patch this weekEPSS 0.600.60
CVE-2024-23113Format StringFortinet Multiple ProductsPatch this weekEPSS 0.620.62
CVE-2024-9379SQL InjectionIvanti Cloud Services Appliance (CSA)Patch soon0.44

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.