CISA's list that day
28 April 2025
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Broadcom Brocade Fabric OS, Commvault Web Server and Qualitia Active! Mail. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-42599Stack-Based Buffer Overflow | Qualitia Active! Mail | Patch soon | 0.03 | ||
| CVE-2025-3928Unspecified | Commvault Web Server | Patch soon | 0.02 | ||
| CVE-2025-1976Code Injection | Broadcom Brocade Fabric OS | Patch soon | 0.01 |