CISA's list that day

17 April 2025

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Apple Multiple Products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-24054NTLM Hash Disclosure SpoofingMicrosoft WindowsPatch this weekEPSS 0.590.59
CVE-2025-31200Memory CorruptionApple Multiple ProductsPatch soon0.19
CVE-2025-31201Arbitrary Read and WriteApple Multiple ProductsPatch soon0.14