CISA remediation directive for CVE-2020-24363
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA ordered federal agencies to address CVE-2020-24363 by September 23, extending a remediation deadline for a TP-Link TL-WA855RE flaw that has been exploited in attacks. The advisory also warns that affected products may be end-of-life or end-of-service and should be discontinued where needed.
Related Happenings
CISA KEV directive for CVE-2026-20133
Public Sector Action
First: 21.04.2026 15:30
Last: 21.04.2026 15:30
Sources 1
About this happening:
On **Monday, April 21, 2026**, **CISA** added **CVE-2026-20133** to the **KEV Catalog** and ordered **FCEB agencies** to secure their networks by **Friday, April 24**. The directi...
CISA KEV directive for CVE-2026-20133
Public Sector ActionAbout this happening: On **Monday, April 21, 2026**, **CISA** added **CVE-2026-20133** to the **KEV Catalog** and ordered **FCEB agencies** to secure their networks by **Friday, April 24**. The directi...
CISA KEV listing and FCEB patch order for Ivanti EPMM
Public Sector Action
First: 08.04.2026 21:15
Last: 08.04.2026 21:15
Sources 1
About this happening:
**CISA** added **CVE-2026-1340** to the **KEV Catalog** and ordered **FCEB agencies** to patch **Ivanti Endpoint Manager Mobile (EPMM)** by **Saturday midnight, April 11**, forcin...
CISA KEV listing and FCEB patch order for Ivanti EPMM
Public Sector ActionAbout this happening: **CISA** added **CVE-2026-1340** to the **KEV Catalog** and ordered **FCEB agencies** to patch **Ivanti Endpoint Manager Mobile (EPMM)** by **Saturday midnight, April 11**, forcin...
CISA KEV listing and FCEB patch order for CVE-2026-35616
Public Sector Action
First: 06.04.2026 19:02
Last: 06.04.2026 19:02
Sources 1
About this happening:
**CISA** added **CVE-2026-35616** to the **KEV Catalog** and ordered **FCEB agencies** to patch **FortiClient EMS** by **Thursday midnight, April 9**. The mandate matters because...
CISA KEV listing and FCEB patch order for CVE-2026-35616
Public Sector ActionAbout this happening: **CISA** added **CVE-2026-35616** to the **KEV Catalog** and ordered **FCEB agencies** to patch **FortiClient EMS** by **Thursday midnight, April 9**. The mandate matters because...
CISA urgent mitigation order for Cisco FMC CVE-2026-20131
Advisory/Mitigation
First: 23.03.2026 12:30
Last: 23.03.2026 12:30
Sources 1
About this happening:
**CISA** ordered **federal civilian agencies** to patch **CVE-2026-20131** in **Cisco Secure Firewall Management Center (FMC)** within **three days** or discontinue use if mitigat...
CISA urgent mitigation order for Cisco FMC CVE-2026-20131
Advisory/MitigationAbout this happening: **CISA** ordered **federal civilian agencies** to patch **CVE-2026-20131** in **Cisco Secure Firewall Management Center (FMC)** within **three days** or discontinue use if mitigat...
CISA BOD 22-01 order for FCEB iOS patching
Public Sector Action
First: 23.03.2026 10:37
Last: 23.03.2026 10:37
Sources 1
About this happening:
**CISA** ordered **FCEB agencies** to secure devices against **DarkSword-linked iOS flaws**, tightening federal exposure to attacks that enabled **sandbox escape** and **remote co...
CISA BOD 22-01 order for FCEB iOS patching
Public Sector ActionAbout this happening: **CISA** ordered **FCEB agencies** to secure devices against **DarkSword-linked iOS flaws**, tightening federal exposure to attacks that enabled **sandbox escape** and **remote co...
Timeline
-
03.09.2025 21:56 2 articles · 8mo ago
CISA adds CVE-2020-24363 to KEV catalog and urges remediation by September 23
Mitigation Patch UpdateCISA warned that TP-Link TL-WA855RE Wi-Fi range extenders are being actively attacked via CVE-2020-24363, a missing authentication flaw that lets a same-network attacker send unauthenticated TDDP_RESET requests, factory reset and reboot the device, and set a new administrative password. The agency added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, directed federal agencies to address it by September 23, and said impacted products may be end-of-life or end-of-service and should be discontinued.
Show sources
- US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack — www.securityweek.com — 03.09.2025 21:56
- US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack — www.securityweek.com — 03.09.2025 21:56