Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV remediation order for CVE-2025-22225

Public Sector Action
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The directive formalized remediation for a VMware ESXi flaw already tied to ransomware campaigns, increasing urgency for government systems exposed to the vulnerability. The action was issued under Binding Operational Directive (BOD) 22-01 and applies to agencies that must either mitigate the flaw or stop using the product if mitigation is unavailable.

Related Happenings

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...

CERT-In 12-hour KEV remediation guidance

Advisory/Mitigation
H score39 First: 26.05.2026 13:30 Last: 26.05.2026 13:30 Sources 1

About this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
H score37 First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

CISA Apache ActiveMQ CVE-2026-34197 mitigation order

Advisory/Mitigation
H score71 First: 21.04.2026 14:17 Last: 21.04.2026 14:17 Sources 1

About this happening: CISA ordered FCEB agencies to secure Apache ActiveMQ servers by April 30 after CVE-2026-34197 was confirmed actively exploited. The flaw can allow arbitr...

Timeline

  1. 04.02.2026 19:38 2 articles · 5mo ago

    CISA KEV remediation order for CVE-2025-22225

    Legal Policy Action Update

    CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025 under Binding Operational Directive (BOD) 22-01. The directive told agencies to apply vendor mitigations or discontinue use of the product if mitigations were unavailable.

    Show sources
  2. 04.02.2026 19:38 1 articles · 5mo ago

    CISA confirms ransomware exploitation of CVE-2025-22225

    Initial Disclosure

    CISA confirmed that ransomware gangs are exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox-escape and arbitrary-write flaw that Broadcom patched in March 2025 after marking it an actively exploited zero-day. The update also aligns with earlier reporting that Chinese-speaking threat actors likely chained related VMware flaws in sophisticated zero-day attacks since at least February 2024.

    Show sources