Home > 취약점 정보 공유 > 보안공지
보안공지

목록

조회수 : 5,185


美 CISA 발표 주요 Exploit 정보공유(Update. 2025-10-24)2025-10-24
현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog

cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2025-59287MicrosoftMicrosoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability2025-10-24Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-14
CVE-2025-54236AdobeAdobe Commerce and Magento Improper Input Validation Vulnerability2025-10-24Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-14
출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog