CISA's list that day
18 March 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Fortinet FortiOS and FortiProxy and tj-actions changed-files GitHub Action. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Code | tj-actions changed-files GitHub Action | Patch this weekEPSS 0.72 | 0.72 | ||
| CVE-2025-24472Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.07 |