CISA added six vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerabilities affect Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler products. BOD 26-04 requires FCEB agencies to prioritize remediation of these vulnerabilities on publicly exposed assets.
BOD 26-04
2 posts
CISA Adds Six Known Exploited Vulnerabilities to Catalog (CVE-2015-3246, CVE-2015-5287, CVE-2019-1068 +3 more) CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-33824, CVE-2026-55040, CVE-2026-59310 +1 more) CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerabilities span Microsoft IKE Service Extensions (double free), Microsoft SharePoint (weak authentication), Broadcom VMware vCenter (path traversal), and Apple macOS (improper authentication). BOD 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation and to check for prior compromise.