Tech

CISA says Oracle and Mitel have critical security flaws being exploited

Share
Share


  • CISA addS three new bugs to KEV – two in Mitel’s MiCollab, and one in Oracle WebLogic Server
  • The bugs allowed crooks to read sensitive files and take over vulnerable endpoints
  • Federal agencies have until late January 2025 to deploy the patch

The US Cybersecurity and Infrastructure Security Agency (CISA) HAS added three new flaws to its Exploited Vulnerabilities Catalog (KEV), signalling in-the-wild abuse, and giving federal agencies a deadline to patch things up.

Two of the three flaws are found in Mitel’s MiCollab unified communications platform. One is a critical path traversal vulnerability, tracked as CVE-2024-41713.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
EVs, tariffs in the spotlight as Chinese automakers take leading role at Shanghai auto show
Tech

EVs, tariffs in the spotlight as Chinese automakers take leading role at Shanghai auto show

A concept car is shown during the Volkswagen Group media night ahead...

Character.AI’s newest feature can bring a picture to uncanny life
Tech

Character.AI’s newest feature can bring a picture to uncanny life

Character.AI’s new AvatarFX tool can turn a single photo into a realistic...

Inside Disney’s high-tech mission to protect the Great Lizard Cuckoo at Lookout Cay
Tech

Inside Disney’s high-tech mission to protect the Great Lizard Cuckoo at Lookout Cay

When Disney Cruise Line opened its new island destination in the Bahamas...