CISA Orders Agencies to Patch Actively Exploited Sophos Firewall Bug
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies on Thursday to patch a critical Sophos firewall bug and seven other vulnerabilities within the next three weeks, all exploited in ongoing attacks.
Two days later, the cybersecurity vendor amended its security advisory, saying it alerted a small set of South Asian organizations targeted with CVE-2022-1040 exploits.
CISA also ordered federal agencies to patch a high severity arbitrary file upload vulnerability (CVE-2022-26871) in the Trend Micro Apex Central product management console that can be abused in remote code execution attacks.
On Tuesday, Trend Micro said it has observed “at least one active attempt of potential exploitation” of this vulnerability in the wild.
CISA added six more vulnerabilities to its Known Exploited Vulnerabilities Catalog today, all of them also exploited in ongoing attacks.
|CVE||Vulnerability Name||Due Date|
|CVE-2022-26871||Trend Micro Apex Central Arbitrary File Upload Vulnerability||2022-04-21|
|CVE-2022-1040||Sophos Firewall Authentication Bypass Vulnerability||2022-04-21|
|CVE-2021-34484||Microsoft Windows User Profile Service Privilege Escalation||2022-04-21|
|CVE-2021-28799||QNAP NAS Improper Authorization Vulnerability||2022-04-21|
|CVE-2021-21551||Dell dbutil Driver Insufficient Access Control Vulnerability||2022-04-21|
|CVE-2018-10562||Dasan GPON Routers Command Injection Vulnerability||2022-04-21|
|CVE-2018-10561||Dasan GPON Routers Authentication Bypass Vulnerability||2022-04-21|
|CVE-2014-6324||Microsoft Windows Kerberos KDC Privilege Escalation||2022-04-21|
According to a November 2021 binding operational directive (BOD 22-01), Federal Civilian Executive Branch Agencies (FCEB) agencies must secure their systems against these security flaws, with CISA giving them until April 21 to patch the ones added today.
“These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise,” the US cybersecurity agency explains.
While the BOD 22-01 directive only applies to FCEB agencies, CISA has also urged private and public sector organizations to prioritize patching these actively abused security bugs to reduce their networks’ exposure to ongoing cyberattacks.
CISA has added hundreds of vulnerabilities to its list of actively exploited bugs after issuing this binding directive, asking US federal agencies to patch them as soon as possible to prevent security breaches.
Since the start of the year, the cybersecurity agency has also ordered agencies to patch actively exploited zero-days in:
- Google Chrome (CVE-2022-1096)
- Mozilla’s Firefox web browser (CVE-2022-26485)
- Google Chrome (CVE-2022-0609) and Adobe Commerce/Magento Open Source (CVE-2022-24086)
- iPhones, iPads, and Macs (CVE-2022-22620)