<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="https://www.cisa.gov/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Alerts</title>
    <link>https://www.cisa.gov/</link>
    <description></description>
    <language>en</language>
    
    <item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-68686&quot; target=&quot;_blank&quot;&gt;CVE-2025-68686&lt;/a&gt; Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a class=&quot;fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-16812&quot; target=&quot;_blank&quot; title=&quot;https://www.cve.org/cverecord?id=cve-2026-16812&quot; id=&quot;menur1n1j&quot; rel=&quot;noreferrer noopener&quot;&gt;CVE-2026-16812&lt;/a&gt; Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a class=&quot;ext&quot; href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Mon, 27 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25224</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation. &amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-16232&quot; target=&quot;_blank&quot;&gt;CVE-2026-16232&lt;/a&gt; Check Point SmartConsole Improper Authentication Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-50522&quot; target=&quot;_blank&quot;&gt;CVE-2026-50522&lt;/a&gt; Microsoft SharePoint Deserialization of Untrusted Data Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Wed, 22 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25207</guid>
    </item>
<item>
  <title>CISA Adds Four Known Exploited Vulnerabilities to Catalog </title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added four new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2021-27137&quot; target=&quot;_blank&quot;&gt;CVE-2021-27137&lt;/a&gt; DD-WRT Stack-Based Buffer Overflow Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-0770&quot; target=&quot;_blank&quot;&gt;CVE-2026-0770&lt;/a&gt; Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-63030&quot; target=&quot;_blank&quot;&gt;CVE-2026-63030&lt;/a&gt; WordPress Core Interpretation Conflict Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-60137&quot; target=&quot;_blank&quot;&gt;CVE-2026-60137&lt;/a&gt; WordPress Core SQL Injection Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 21 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25194</guid>
    </item>
<item>
  <title>CISA Adds Three Known Exploited Vulnerabilities to Catalog </title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added three new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-25089&quot; target=&quot;_blank&quot;&gt;CVE-2026-25089&lt;/a&gt; Fortinet FortiSandbox OS Command Injection Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-39808&quot; target=&quot;_blank&quot;&gt;CVE-2026-39808&lt;/a&gt; Fortinet FortiSandbox OS Command Injection Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-58644&quot; target=&quot;_blank&quot;&gt;CVE-2026-58644&lt;/a&gt; Microsoft SharePoint Deserialization of Untrusted Data Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Thu, 16 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25182</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2023-4346&quot; target=&quot;_blank&quot;&gt;CVE-2023-4346&lt;/a&gt; KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-46817&quot; target=&quot;_blank&quot;&gt;CVE-2026-46817&lt;/a&gt; Oracle E-Business Suite Improper Privilege Management Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Wed, 15 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25166</guid>
    </item>
<item>
  <title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added four new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-15409&quot; target=&quot;_blank&quot;&gt;CVE-2026-15409&lt;/a&gt; SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-15410&quot; target=&quot;_blank&quot;&gt;CVE-2026-15410&lt;/a&gt; SonicWall SMA1000 Appliances Code Injection Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-56155&quot; target=&quot;_blank&quot;&gt;CVE-2026-56155&lt;/a&gt; Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-56164&quot; target=&quot;_blank&quot;&gt;CVE-2026-56164&lt;/a&gt; Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a class=&quot;ext&quot; href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 14 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25157</guid>
    </item>
<item>
  <title>CISA Urges SharePoint Hardening After New Exploitations</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations</link>
  <description>&lt;p&gt;&lt;strong&gt;Update July 16, 2026&lt;/strong&gt;:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;CISA is aware of active exploitation of vulnerabilities &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-32201&quot; target=&quot;_blank&quot;&gt;CVE-2026-32201&lt;/a&gt;, &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-45659&quot; target=&quot;_blank&quot;&gt;CVE-2026-45659&lt;/a&gt;, &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-56164&quot; target=&quot;_blank&quot;&gt;CVE-2026-56164&lt;/a&gt;, and &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-58644&quot; target=&quot;_blank&quot;&gt;CVE-2026-58644&lt;/a&gt;, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Additionally, the following newly disclosed CVE is&amp;nbsp;not yet known to have been exploited, but Microsoft has identified it&amp;nbsp;as posing a potential risk if left unpatched:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-55040&quot; target=&quot;_blank&quot;&gt;CVE-2026-55040&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CISA urges organizations to detect and remediate a potential compromise by implementing the following recommendations:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Apply the latest patches and security updates from Microsoft, verify that installation completes successfully, and shorten patching cycles when possible.&lt;/li&gt;
&lt;li&gt;Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application. Follow Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration&quot; target=&quot;_blank&quot;&gt;Configure AMSI integration with SharePoint Server&lt;/a&gt; guidance to ensure proper configuration and select the “Full Mode” option for the Request Body Scan Mode, where feasible. When compromise is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV) detections, and implement your organization’s incident response plan for any positive detections:&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;AMSI: &lt;code&gt;Exploit:Script/SuspSignoutReqBody.A&lt;/code&gt; – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts.&lt;/li&gt;
&lt;li&gt;AMSI: &lt;code&gt;Exploit:Script/ToolPaneAuthBypass.A&lt;/code&gt; – request header scanning; SharePoint Server 2016, 2019, and Subscription Edition.&lt;/li&gt;
&lt;li&gt;AMSI: &lt;code&gt;Exploit:Script/ToolPaneAuthBypass.C&lt;/code&gt; – RCE coverage; SharePoint Server 2016, 2019, and Subscription Edition.&lt;/li&gt;
&lt;li&gt;MDAV: &lt;code&gt;Backdoor:MSIL/LeakFang.A!dha&lt;/code&gt; – post-exploitation activity alert involving IIS-protected secrets.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In addition, CISA recommends that organizations implement the following SharePoint Server hardening measures:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Before rotating IIS machine keys, hunt for and remediate any intrusion artifacts, including machine-key harvesters, that could allow for the keys to be stolen again. Review Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/improved-asp-net-view-state-security-key-management#automatic-machine-key-rotation&quot; target=&quot;_blank&quot;&gt;Improved ASP.NET view state security and key management&lt;/a&gt; for best practices.&lt;/li&gt;
&lt;li&gt;Establish tailored logging mechanisms to detect and monitor exploitation activities. Review telemetry for anomalous requests, suspicious SharePoint worker-process activity, webshells, and machine-key access.&amp;nbsp;For more information, see CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/best-practices-event-logging-and-threat-detection&quot;&gt;Best Practices for Event Logging and Threat Detection&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Avoid exposing SharePoint Servers directly to the internet unless necessary; and if necessary, only configure a SharePoint Server behind a Layer 7 reverse proxy or equivalent application-layer security control that requires authentication and can inspect and filter requests.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Block external access to SharePoint Central Administration, restrict farm and database communications to required systems, and review &lt;a href=&quot;https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/security-hardening&quot; target=&quot;_blank&quot;&gt;Microsoft’s SharePoint Server security-hardening guidance&lt;/a&gt; for role-specific ports, services, and &lt;code&gt;Web.config&lt;/code&gt; settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CISA urges users and administrators to review the Alert &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/07/20/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities&quot;&gt;UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities&lt;/a&gt; and apply necessary updates.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;CISA added the following vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;: CVE-2026-32201 on April 14, 2026; CVE-2026-45659 on July 1, 2026; CVE-2026-56164 on July 14, 2026; and CVE-2026-58644 on July 16, 2026.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt;&amp;nbsp;CISA may update this Alert to reflect new guidance issued by CISA or other parties.&lt;/p&gt;
&lt;p&gt;Organizations should report incidents or anomalous activity to CISA via CISA’s 24/7 Operations Center at &lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt; or 1-844-Say-CISA (1-844-729-2472).&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. &lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Acknowledgements&lt;/strong&gt;&amp;nbsp;&lt;/h2&gt;
&lt;p&gt;Microsoft contributed to this Alert.&lt;br&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 14 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25148</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://edit.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2008-4128&quot; target=&quot;_blank&quot;&gt;CVE-2008-4128&lt;/a&gt; Cisco IOS Cross-Site Request Forgery Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a class=&quot;ext&quot; href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Mon, 13 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25145</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog </title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48939&quot; target=&quot;_blank&quot;&gt;CVE-2026-48939&lt;/a&gt; iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-56291&quot; target=&quot;_blank&quot;&gt;CVE-2026-56291&lt;/a&gt; Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Fri, 10 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25143</guid>
    </item>
<item>
  <title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added three new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48908&quot; target=&quot;_blank&quot;&gt;CVE-2026-48908&lt;/a&gt; JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-55255&quot; target=&quot;_blank&quot;&gt;CVE-2026-55255&lt;/a&gt; Langflow Authorization Bypass Through User-Controlled Key Vulnerability &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-56290&quot; target=&quot;_blank&quot;&gt;CVE-2026-56290&lt;/a&gt; Joomlack Page Builder Improper Access Control Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 07 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25116</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48282&quot; target=&quot;_blank&quot;&gt;CVE-2026-48282&lt;/a&gt; Adobe ColdFusion Path Traversal Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 07 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25133</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-45659&quot; target=&quot;_blank&quot;&gt;CVE-2026-45659&lt;/a&gt; Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Wed, 01 Jul 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25105</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/29/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48558&quot; target=&quot;_blank&quot;&gt;CVE-2026-48558&lt;/a&gt; SimpleHelp Authentication Bypass Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Mon, 29 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25087</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation. &amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-12569&quot; target=&quot;_blank&quot;&gt;CVE-2026-12569&lt;/a&gt; PTC Windchill and FlexPLM Improper Input Validation Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-20230&quot; target=&quot;_blank&quot;&gt;CVE-2026-20230&lt;/a&gt; Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Thu, 25 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25083</guid>
    </item>
<item>
  <title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added four new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation. &amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-67038&quot; target=&quot;_blank&quot;&gt;CVE-2025-67038&lt;/a&gt; Lantronix EDS5000 Code Injection Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-34908&quot; target=&quot;_blank&quot;&gt;CVE-2026-34908&lt;/a&gt; Ubiquiti UniFi OS Improper Access Control Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-34909&quot; target=&quot;_blank&quot;&gt;CVE-2026-34909&lt;/a&gt; Ubiquiti UniFi OS Path Traversal Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-34910&quot; target=&quot;_blank&quot;&gt;CVE-2026-34910&lt;/a&gt; Ubiquiti UniFi OS Improper Input Validation Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 23 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25060</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-20253&quot; target=&quot;_blank&quot;&gt;CVE-2026-20253&lt;/a&gt; Splunk Enterprise Missing Authentication for Critical Function Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating &lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities-revoked&quot;&gt;BOD 22-01&lt;/a&gt;. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit for potential addition: &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Thu, 18 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25042</guid>
    </item>
<item>
  <title>CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure</link>
  <description>&lt;p&gt;&lt;strong&gt;Update June 22, 2026:&lt;/strong&gt;&lt;br&gt;&lt;em&gt;CISA has updated this Alert to incorporate the link to Fortinet’s recent guidance on this activity.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;To defend against this malicious cyber activity, CISA urges impacted Fortinet customers with FortiGate appliances and associated secure sockets layer (SSL) VPN gateways to immediately:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Terminate sessions and reset credentials.&lt;/strong&gt; Terminate all active SSL VPN and administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ensure secure credential storage.&lt;/strong&gt; Confirm your organization’s use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes per Fortinet’s guidance (see, &lt;a href=&quot;https://community.fortinet.com/fortigate-3/technical-tip-enforcing-pbkdf2-as-hash-function-for-administrator-accounts-in-fortios-v7-2-11-and-later-220652&quot; target=&quot;_blank&quot;&gt;Fortinet&#039;s Technical Tip: Enforcing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 and later&lt;/a&gt;). &amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review logs.&lt;/strong&gt; Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enable phishing-resistant multifactor authentication (MFA).&lt;/strong&gt; &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf&quot;&gt;Require phishing-resistant MFA&lt;/a&gt; on all remote access and administrative accounts and ensure it is enforced on all external gateways and administrative interfaces.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduce the attack surface and lock down management access.&lt;/strong&gt; Ensure the administration of your firewall is inaccessible from the public internet; restrict Fortinet management interfaces to trusted internal networks; and remove or disable any unauthorized or unnecessary accounts.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;See the following resources to determine your organization’s potential impact and find additional guidance on the credentials compromised:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tech Times: &lt;a href=&quot;https://www.techtimes.com/articles/318599/20260618/fortinet-fortigate-credential-leak-hits-73932-firewalls-half-internet-facing-fleet.htm&quot; target=&quot;_blank&quot;&gt;Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: Half the Internet-Facing Fleet&lt;/a&gt; &amp;nbsp;&lt;/li&gt;
&lt;li&gt;SOCRadar: &lt;a href=&quot;https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/&quot; target=&quot;_blank&quot;&gt;FortiBleed: The Compromise of 80,000+ Fortinet Firewalls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hudson Rock: &lt;a href=&quot;https://www.hudsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure&quot; target=&quot;_blank&quot;&gt;FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Arctic Wolf: &lt;a href=&quot;https://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/&quot; target=&quot;_blank&quot;&gt;Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fortinet: &lt;a href=&quot;https://www.fortinet.com/blog/industry-trends/attacks-at-the-speed-of-ai&quot; target=&quot;_blank&quot;&gt;Attacks at the Speed of AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fortinet: &lt;a href=&quot;https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices&quot; target=&quot;_blank&quot;&gt;Analysis of Reported Credential Compromise of FortiGate Devices&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.&lt;/p&gt;
</description>
  <pubDate>Thu, 18 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25052</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48907&quot; target=&quot;_blank&quot;&gt;CVE-2026-48907&lt;/a&gt; Widget Factory Joomla Content Editor Improper Access Control Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating &lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;BOD 22-01&lt;/a&gt;. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 16 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25040</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-20262&quot; target=&quot;_blank&quot;&gt;CVE-2026-20262&lt;/a&gt; Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-54420&quot; target=&quot;_blank&quot;&gt;CVE-2026-54420&lt;/a&gt; LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating &lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;BOD 22-01&lt;/a&gt;. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&lt;/p&gt;
</description>
  <pubDate>Mon, 15 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25028</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/12/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-35273&quot; target=&quot;_blank&quot;&gt;CVE-2026-35273&lt;/a&gt; Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating &lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities-revoked&quot;&gt;BOD 22-01&lt;/a&gt;. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit for potential addition: &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Fri, 12 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25021</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/11/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10520&quot; target=&quot;_blank&quot;&gt;CVE-2026-10520&lt;/a&gt; Ivanti Sentry OS Command Injection Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&quot;&gt;Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk&lt;/a&gt; establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating &lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities-revoked&quot;&gt;BOD 22-01&lt;/a&gt;. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.&lt;/p&gt;
&lt;p&gt;While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit for potential addition: &lt;a href=&quot;https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w&quot; target=&quot;_blank&quot;&gt;KEV Nomination Form&lt;/a&gt;. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Thu, 11 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25018</guid>
    </item>
<item>
  <title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added three new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7473&quot; target=&quot;_blank&quot;&gt;CVE-2026-7473&lt;/a&gt; Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11645&quot; target=&quot;_blank&quot;&gt;CVE-2026-11645&lt;/a&gt; Google Chromium V8 Out-of-Bounds Read and Write Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-20245&quot; target=&quot;_blank&quot;&gt;CVE-2026-20245&lt;/a&gt; Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Tue, 09 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25008</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-42271&quot; target=&quot;_blank&quot;&gt;CVE-2026-42271&lt;/a&gt; BerriAI LiteLLM Command Injection Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-50751&quot; target=&quot;_blank&quot;&gt;CVE-2026-50751&lt;/a&gt; Check Point Security Gateway Improper Authentication Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Mon, 08 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24998</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/05/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-28318&quot; target=&quot;_blank&quot;&gt;CVE-2026-28318&lt;/a&gt; SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Fri, 05 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24995</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-45247&quot; target=&quot;_blank&quot;&gt;CVE-2026-45247&lt;/a&gt;&amp;nbsp;Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
</description>
  <pubDate>Wed, 03 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24988</guid>
    </item>
<item>
  <title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added two new vulnerabilities to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2022-0492&quot; target=&quot;_blank&quot;&gt;CVE-2022-0492&lt;/a&gt; Linux Kernel Improper Authentication Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-48595&quot; target=&quot;_blank&quot;&gt;CVE-2025-48595&lt;/a&gt; Android Framework Integer Overflow Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
</description>
  <pubDate>Tue, 02 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24976</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-21182&quot; target=&quot;_blank&quot;&gt;CVE-2024-21182&lt;/a&gt; Oracle WebLogic Server Unspecified Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt;&amp;nbsp;established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
</description>
  <pubDate>Mon, 01 Jun 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24969</guid>
    </item>
<item>
  <title>CISA Adds One Known Exploited Vulnerability to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/29/cisa-adds-one-known-exploited-vulnerability-catalog</link>
  <description>&lt;p&gt;CISA has added one new vulnerability to its &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-0257&quot; target=&quot;_blank&quot;&gt;CVE-2026-0257&lt;/a&gt; Palo Alto Networks PAN-OS Authentication Bypass Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt; established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of &lt;a href=&quot;/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt; as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Fri, 29 May 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24965</guid>
    </item>
<item>
  <title>Supply Chain Compromises Impact Nx Console and GitHub Repositories</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories</link>
  <description>&lt;p&gt;CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments—specifically CI/CD pipelines, code extensions and workflows.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Threat actors leveraged a prior compromise of Nx developer systems to compromise a GitHub employee’s device&amp;nbsp;through a poisoned third-party VS Code extension, resulting in unauthorized access and exfiltration of internal GitHub repositories. The malicious extension version (18.95.0) was distributed through VS Code’s automatic update mechanism, meaning systems with Nx Console previously installed may have received the malicious build without developers taking any manual installation action. GitHub released a &lt;a href=&quot;https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w&quot; target=&quot;_blank&quot;&gt;security advisory&lt;/a&gt; on this activity, and &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48027&quot; target=&quot;_blank&quot;&gt;CVE-2026-48027&lt;/a&gt; has been assigned to the malicious version of Nx Console and added to &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;CISA’s Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Additionally, in a campaign known as “Megalodon,” a cyber threat actor injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories.&lt;/p&gt;
&lt;p&gt;CISA urges organizations to implement the following recommendations to detect and remediate a potential compromise:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Monitor and audit workflow files and contributor activity for suspicious pull requests and direct commits, particularly those authored by automated accounts.&lt;/li&gt;
&lt;li&gt;Revert unauthorized changes, especially from automated accounts, e.g., &lt;code&gt;build-bot&lt;/code&gt;, &lt;code&gt;auto-ci&lt;/code&gt;, &lt;code&gt;ci-bot&lt;/code&gt;, &lt;code&gt;pipeline-bot&lt;/code&gt; and especially those made after May 18, 2026.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If your organization discovers a compromise resulting from previously compromised GitHub or Nx Console software, CISA recommends the following steps:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Conduct a forensics review of CI/CD logs, cloud audit trails, and affected developer machines.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Rotate/revoke all secrets including: all credentials, tokens, and secrets accessible to CI/CD pipelines, including API keys, cloud provider credentials (Amazon Web Services, Google Cloud Platform, Microsoft Azure), SSH keys, Docker/npm/PyPI/Vault/Terraform/Kubernetes tokens, GitHub/GitLab/Bitbucket tokens, and developer or pipeline secrets.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Notify proper stakeholders if necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CISA recommends the following best practices for using package repos:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Wait at least three hours before pulling a new package. This gives the software community time to identify suspicious or malicious packages before they are widely downloaded.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Pin software to specific trusted versions. Pinning software prevents pulling a malicious or unscreened package during the build process.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Only pull packages from known and trusted sources. Relying on known and trusted sources reduces the likelihood of downloading a package that has been maliciously forked.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;See the following resources for additional guidance on these compromises:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;GitHub: &lt;a href=&quot;https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/&quot; target=&quot;_blank&quot;&gt;Investigating unauthorized access to GitHub-owned repositories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nx:&amp;nbsp;&lt;a href=&quot;https://nx.dev/blog/nx-console-v18-95-0-postmortem&quot; target=&quot;_blank&quot;&gt;Postmortem: Nx Console v18.95.0 supply-chain compromise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ox Security: &lt;a href=&quot;https://www.ox.security/blog/megalodon-cicd-malware-github/&quot; target=&quot;_blank&quot;&gt;Megalodon: CI/CD Malware Spreading Across GitHub Repositories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;StepSecurity: &lt;a href=&quot;https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised#indicators-of-compromise&quot; target=&quot;_blank&quot;&gt;Nx Console VS Code Extension Compromised&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;SafeDep: &lt;a href=&quot;https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/&quot; target=&quot;_blank&quot;&gt;Megalodon: Mass GitHub Repo Backdooring via CI Workflows&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. &amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Thu, 28 May 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24961</guid>
    </item>
<item>
  <title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
  <link>https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
  <description>&lt;p&gt;CISA has added&amp;nbsp;three&amp;nbsp;new vulnerabilities&amp;nbsp;to its&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt;, based on evidence of active exploitation.&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-8398&quot; target=&quot;_blank&quot;&gt;CVE-2026-8398&lt;/a&gt;&amp;nbsp;Daemon Tools Lite Embedded Malicious Code Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-45321&quot; target=&quot;_blank&quot;&gt;CVE-2026-45321&lt;/a&gt;&amp;nbsp;TanStack&amp;nbsp;Unspecified Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-48027&quot; target=&quot;_blank&quot;&gt;CVE-2026-48027&lt;/a&gt;&amp;nbsp;Nx Console Embedded Malicious Code Vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These&amp;nbsp;types&amp;nbsp;of vulnerabilities are&amp;nbsp;frequent attack vectors&amp;nbsp;for malicious cyber actors and pose significant risks to the federal enterprise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.cisa.gov/binding-operational-directive-22-01&quot;&gt;Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities&lt;/a&gt;&amp;nbsp;established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf&quot;&gt;BOD 22-01 Fact Sheet&lt;/a&gt;&amp;nbsp;for more information.&lt;/p&gt;
&lt;p&gt;Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing&amp;nbsp;timely&amp;nbsp;remediation of&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;KEV Catalog vulnerabilities&lt;/a&gt;&amp;nbsp;as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities&quot;&gt;specified criteria&lt;/a&gt;.&lt;/p&gt;
</description>
  <pubDate>Wed, 27 May 26 12:00:00 +0000</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24943</guid>
    </item>

  </channel>
</rss>
