CISA says Oracle and Mitel have critical security flaws that are being exploited


  • CISA adds three new bugs to KEV: two in Mitel’s MiCollab and one in Oracle WebLogic Server
  • The bugs allowed criminals to read sensitive files and take over vulnerable endpoints.
  • Federal agencies have until the end of January 2025 to implement the patch.

The US Cybersecurity and Infrastructure Security Agency (CISA) HAS added three new flaws to its Catalog of Exploited Vulnerabilities (KEV), indicating abuse in the wild and giving federal agencies a deadline to fix the things.

Two of the three flaws are in Mitel’s MiCollab unified communications platform. One is a critical path traversal vulnerability, tracked as CVE-2024-41713.

Leave a Comment

Your email address will not be published. Required fields are marked *