Fact-check: The article cites an official CISA source and aligns with CISA's established practices for updating the KEV Catalog and issuing directives like BOD 22-01, which is a verified policy. While the date in the URL appears anomalous, the core claims about vulnerabilities and remediation requirements are consistent with CISA's ongoing operations in the Critical Infrastructure situation.
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has added five newly confirmed exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including flaws in the Linux Kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils. Federal Civilian Executive Branch agencies are required to remediate these vulnerabilities by designated due dates under Binding Operational Directive 22-01. CISA urges all organizations to prioritize patching these vulnerabilities as part of standard vulnerability management practic