All news with #android runtime tag
Thu, September 4, 2025
CISA Adds Three CVEs to Known Exploited Vulnerabilities
#KEV Added
#Security Advisory
#Insecure Deserialization
#Race Condition
#Linux Kernel
#Android Runtime
#Sitecore
🔔 CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-38352 (Linux kernel TOCTOU race condition), CVE-2025-48543 (Android Runtime unspecified vulnerability), and CVE-2025-53690 (Sitecore multiple-products deserialization). Under BOD 22-01, Federal Civilian Executive Branch agencies must remediate cataloged CVEs by the required due dates. Although the directive applies to FCEB agencies, CISA strongly urges all organizations to prioritize timely remediation, patching, and vulnerability management to reduce exposure to active exploitation.