CISA's list that day
20 February 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Palo Alto Networks PAN-OS and Craft CMS. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-23209Code Injection | Craft CMS Craft CMS | Patch soon | 0.22 | ||
| CVE-2025-0111File Read | Palo Alto Networks PAN-OS | Patch soon | 0.02 |