CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet

CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet

The U.S. CISA has added three critical security flaws affecting AMI MegaRAC, D-Link DIR-859 routers, and Fortinet FortiOS to its KEV catalog due to active exploitation. These vulnerabilities pose serious risks, including remote control, privilege escalation, and data decryption. #AMI MegaRAC #D-Link DIR-859 #Fortinet FortiOS

Keypoints

  • Three security flaws have been added to CISA’s KEV catalog with evidence of active exploitation.
  • CVE-2024-54085 in AMI MegaRAC allows remote control through an authentication bypass.
  • CVE-2024-0769 in D-Link DIR-859 routers enables privilege escalation; the device is unpatched due to end-of-life status.
  • CVE-2019-6693 in Fortinet products involves hard-coded cryptographic keys, risking password decryption.
  • Federal agencies must implement mitigations by July 16, 2025, to protect against these vulnerabilities.

Read More: https://thehackernews.com/2025/06/cisa-adds-3-flaws-to-kev-catalog.html