The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting popular networking and server management systems.
## Critical Vulnerabilities Under Active Attack
**AMI MegaRAC Authentication Bypass (CVE-2024-54085)**
– **Severity**: Critical (CVSS 10.0)
– **Impact**: Remote attackers can bypass authentication and gain complete system control
– **Risk**: Enables malware deployment and firmware tampering
– **Discovery**: Disclosed by firmware security firm Eclypsium
**D-Link DIR-859 Router Path Traversal (CVE-2024-0769)**
– **Severity**: Medium (CVSS 5.3)
– **Impact**: Allows privilege escalation and unauthorized access
– **Status**: Unpatched and unfixable – routers reached end-of-life in December 2020
– **Exploitation**: Used to steal user credentials and account information
– **Recommendation**: Replace affected devices immediately
**Fortinet Hard-coded Encryption Key (CVE-2019-6693)**
– **Severity**: Medium (CVSS 4.2)
– **Impact**: Exposes encrypted password data in configuration files
– **Threat Actor**: Exploited by Akira ransomware group for network infiltration
– **Affected Products**: FortiOS, FortiManager, and FortiAnalyzer
## Current Threat Landscape
Security researchers have documented active exploitation campaigns targeting these vulnerabilities. The D-Link router flaw has been exploited for credential theft, while the Fortinet vulnerability serves as an entry point for ransomware attacks.
The AMI MegaRAC vulnerability poses the highest risk due to its critical severity rating and potential for complete system compromise, though specific attack details remain undisclosed.
## Federal Response Requirements
Federal agencies must implement security patches and mitigations by **July 16, 2025**, as mandated by CISA’s binding operational directive for Federal Civilian Executive Branch organizations.
Organizations using affected systems should prioritize immediate patching where available, or device replacement for end-of-life products like the D-Link DIR-859 router.
