CISA's list that day
8 April 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Gladinet CentreStack. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-30406and Triofox Use of Hard-coded Cryptographic Key | Gladinet CentreStack | Patch this weekMetasploit module; EPSS 0.94 | 0.94 | ||
| CVE-2025-29824Common Log File System (CLFS) Driver Use-After-Free | Microsoft Windows | Patch this weekRansomware use | 0.14 |