CISA's list that day

16 December 2024

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Adobe ColdFusion and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-20767Improper Access ControlAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.990.99
CVE-2024-35250Kernel-Mode Driver Untrusted Pointer DereferenceMicrosoft WindowsPatch this weekMetasploit module0.25

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.