← Back to news

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Cybersecurity Advisories08/12/2025, 12:00
Read full article →

Summary

AI-Generated

Key Points:

  • CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-37055 and CVE-2025-66644.
  • The vulnerabilities include a buffer overflow in D-Link routers and a command injection vulnerability in Array Networks ArrayOS, both of which are actively exploited.
  • Organizations should prioritize patching these vulnerabilities to mitigate the risk of exploitation.

Technical Details: CVE-2022-37055 is a buffer overflow vulnerability affecting D-Link routers, while CVE-2025-66644 pertains to command injection in Array Networks' ArrayOS. Both vulnerabilities have been confirmed to be actively exploited in the wild.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.