By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA
Tech News

Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA

By Viral Trending Content 2 Min Read
Share
SHARE

Feb 25, 2025Ravie LakshmananNetwork Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws impacting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerabilities in question are listed below –

  • CVE-2017-3066 (CVSS score: 9.8) – A deserialization vulnerability impacting Adobe ColdFusion in the Apache BlazeDS library that allows for arbitrary code execution. (Fixed in April 2017)
  • CVE-2024-20953 (CVSS score: 8.8) – A deserialization vulnerability impacting Oracle Agile PLM that allows a low-privileged attacker with network access via HTTP to compromise the system. (Fixed in January 2024)

There are currently no public reports referencing the exploitation of the vulnerabilities, although another flaw impacting Oracle Agile PLM (CVE-2024-21287, CVSS score: 7.5) came under active abuse late last year.

Cybersecurity

To mitigate the risks posed by potential attacks weaponizing these flaws, it’s recommended that users take steps to apply the necessary updates. Federal agencies have time until March 17, 2025, to secure their networks against the threats.

The development comes as threat intelligence firm GreyNoise revealed active exploitation attempts targeting CVE-2023-20198, a now-patched security flaw affecting vulnerable Cisco devices.

As many as 110 malicious IPs, mainly originating from Bulgaria, Brazil, and Singapore have been linked to the malicious activity.

“Two malicious IPs exploited CVE-2018-0171 in December 2024 and January 2025, originating from Switzerland and the United States — the same period when Salt Typhoon, a Chinese state-sponsored threat group, reportedly breached telecom networks using CVE-2023-20198 and CVE-2023-20273,” the GreyNoise Research Team said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

After Struggling With EVs, US Automakers Pivot to Energy

Microsoft releases Windows 10 KB5082200 extended security update

Trump Phone T1 Launches in US: Design, Features, Background

AGIBOT A2 Brings Embodied AI to the Met Gala Alongside Alexander Wang

TAGGED: adobe, CISA, Cyber Security, Cybersecurity, Federal Security, Internet, network security, Oracle, software security, Threat Intelligence, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article BP to abandon pledge to cut oil and gas output as boss fights for group’s survival
Next Article Apple Forced to Withdraw Advanced Data Protection in The UK
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

U.S. employers added a surprising 115,000 jobs last month despite the economic shock from Iran war
Business
Bitwise launches US-listed Hyperliquid fund with staking rewards
Crypto
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Tech News
MemoryCore combines the best PS1 games in one stylish new TTRPG
Gaming News
All Charleroi Airport flights to be grounded on Tuesday amid national strikes
Travel
After Struggling With EVs, US Automakers Pivot to Energy
Tech News
Microsoft releases Windows 10 KB5082200 extended security update
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

U.S. employers added a surprising 115,000 jobs last month despite the economic shock from Iran war

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
U.S. employers added a surprising 115,000 jobs last month despite the economic shock from Iran war
May 17, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?