System administrators managing critical infrastructure and enterprise networks must prioritize urgent patching. Three high-severity vulnerabilities, confirmed to be actively exploited in the wild, have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, marking them as immediate threats requiring action.

CISA's addition of these flaws to its KEV catalog signals a critical risk for all organizations due to the widespread use of the affected Check Point, F5, and Arista products in enterprise environments. While the directive applies to U.S. federal agencies, which must remediate within standard KEV timelines, the active exploitation of these flaws demands immediate attention from security teams globally.

The most critical flaw (CVE-2025-22457, CVSS 9.8) is a buffer overflow in the IPsec VPN negotiation process of Check Point Security Gateways. This vulnerability allows an unauthenticated attacker to remotely execute arbitrary code. Given that internet-facing VPN gateways are a primary target for threat actors, this flaw requires immediate attention.

Also rated critical (CVSS 9.8) is an authenticated file upload vulnerability in the F5 BIG-IP Access Policy Manager (CVE-2024-46820). Successful exploitation enables command execution on the system. F5 application delivery controllers are another common component in enterprise networks, making this a high-priority risk.

A third critical vulnerability (CVSS 9.8) in the Arista VeloCloud Orchestrator (CVE-2024-47575) allows unauthenticated arbitrary file uploads due to a missing authentication check on an endpoint. Its inclusion in the KEV catalog confirms it is under active attack.

For IT teams, this advisory necessitates a clear action plan: immediately audit networks for instances of the affected products, with special focus on internet-facing systems, especially VPN concentrators. Teams must cross-reference internal asset inventories with official vendor advisories for precise patch and mitigation guidance, as details such as CVE identifiers can vary.

The inclusion of these flaws in the KEV catalog shifts their status from a theoretical risk to a confirmed, active threat. This should directly inform and accelerate vulnerability management cycles, making the remediation of these specific vulnerabilities a non-negotiable priority for system administrators.


管理關鍵基礎設施和企業網絡的系統管理員必須優先處理緊急修補工作。三個已證實在野外被積極利用的高嚴重性漏洞,已被加入美國網絡安全和基礎設施安全局(CISA)的已知被利用漏洞(KEV)目錄,標誌為需要立即採取行動的即時威脅。

由於受影響的 Check Point、F5 和 Arista 產品在企業環境中廣泛使用,CISA 將這些漏洞加入其 KEV 目錄,對所有組織均發出關鍵風險信號。雖然該指令適用於必須在標準 KEV 時間框架內完成補救的美國聯邦機構,但這些漏洞正被積極利用的情況,要求全球安全團隊立即關注。

最關鍵的漏洞(CVE-2025-22457,CVSS 9.8)是 Check Point 安全網關 IPsec 虛擬專用網絡協商過程中的緩衝區溢出。此漏洞允許未經身份驗證的攻擊者遠程執行任意代碼。鑑於面向互聯網的虛擬專用網絡網關是威脅行為者的主要目標,此漏洞需要立即關注。

同樣被評為關鍵(CVSS 9.8)的是 F5 BIG-IP 存取策略管理器中的已驗證文件上傳漏洞(CVE-2024-46820)。成功利用此漏洞可在系統上執行命令。F5 應用交付控制器是企業網絡中的另一個常見組件,使其成為高優先級風險。

Arista VeloCloud Orchestrator 中的第三個關鍵漏洞(CVSS 9.8)(CVE-2024-47575)由於端點缺少身份驗證檢查,允許未經身份驗證的任意文件上傳。其被列入 KEV 目錄證實其正遭受活躍攻擊。

對 IT 團隊而言,此公告要求制定明確的行動計劃:立即審計網絡中所有受影響產品的實例,特別關注面向互聯網的系統,尤其是虛擬專用網絡集中器。團隊必須將內部資產清單與官方供應商公告交叉參考,以獲取精確的修補和緩解指南,因為 CVE 標識符等細節可能有所不同。

將這些漏洞加入 KEV 目錄,將其地位從理論風險提升為已確認的活躍威脅。這應直接通知並加速漏洞管理週期,使這些特定漏洞的補救成為系統管理員不可協商的優先事項。

新聞來源 / Original News Source