CISA's list that day

8 April 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Gladinet CentreStack. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-30406and Triofox Use of Hard-coded Cryptographic KeyGladinet CentreStackPatch this weekMetasploit module; EPSS 0.940.94
CVE-2025-29824Common Log File System (CLFS) Driver Use-After-FreeMicrosoft WindowsPatch this weekRansomware use0.14