The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ScienceLogic SL1 flaw CVE-2024-9537 to its Known Exploited Vulnerabilities catalog.
ScienceLogic SL1 contains a vulnerability related to a third-party component, which has been fixed in certain versions with patches available for older versions.
Rackspace reported a security breach related to the ScienceLogic EM7 monitoring tool, where a threat actor exploited a zero-day vulnerability in a non-Rackspace utility.
CISA orders federal agencies to fix the ScienceLogic SL1 flaw by November 11, 2024.