CISA has added CVE-2026-20253, a missing authentication vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. The vulnerability allows unauthorized access to critical functions, and organizations are strongly advised to prioritize remediation, particularly for publicly exposed assets that could grant total control post-exploitation.
CISA
27 posts
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-20253) CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-20262, CVE-2026-54420) CISA has added two actively exploited vulnerabilities, CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager and CVE-2026-54420 affecting the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are urged to prioritize remediation of these flaws, particularly on publicly exposed assets, and to investigate for potential pre-patch compromise in alignment with risk-based vulnerability management practices outlined in BOD 26-04.
Naxclow IoT Platform (CVE-2026-42947, CVE-2026-50108, CVE-2026-50101 +4 more) Seven vulnerabilities, including critical flaws, have been identified in the Naxclow IoT Platform affecting various smart home devices. These vulnerabilities stem from hard-coded cryptographic keys, missing authorization, predictable identifiers, and exposed UART consoles, enabling attackers to perform device takeovers, intercept communications, and extract sensitive network credentials.
CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) CISA has added three actively exploited vulnerabilities (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) affecting Arista EOS, Google Chromium V8, and Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these systems to reduce their exposure to ongoing cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-28318) CISA has added CVE-2026-28318, an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247) CISA has added CVE-2026-45247, a deserialization of untrusted data vulnerability affecting the Mirasvit Full Page Cache Warmer, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation, and CISA strongly urges all organizations to prioritize its remediation to reduce exposure to cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595) CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2022-0492, a Linux Kernel improper authentication vulnerability, and CVE-2025-48595, an Android Framework integer overflow vulnerability, citing evidence of active exploitation in the wild.
CISA and Partners Urge Hardening Automatic Tank Gauge Systems (2026-06-02) CISA and partner agencies have observed unattributed malicious cyber activity targeting internet-exposed Automatic Tank Gauge (ATG) systems across multiple U.S. critical infrastructure sectors. Threat actors are leveraging authentication bypass, hardcoded credentials, and command execution vulnerabilities to gain administrative control, enabling them to manipulate tank parameters, disable safety alerts, and create denial-of-view conditions.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2024-21182) CISA has added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-42897 CISA has added CVE-2026-42897, a Cross-Site Scripting (XSS) vulnerability in Microsoft Exchange Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation of this flaw to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate this vulnerability per BOD 22-01, and all organizations are strongly urged to prioritize patching to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-0300, an out-of-bounds write vulnerability affecting Palo Alto Networks PAN-OS, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-31431, an 'Incorrect Resource Transfer Between Spheres' vulnerability affecting the Linux Kernel, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize the timely remediation of this vulnerability to reduce their exposure to cyberattacks.
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new actively exploited vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and D-Link DIR-823X devices. Organizations are strongly urged to prioritize patching these flaws, which include path traversal and command injection vectors, to reduce their exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-39987, a Remote Code Execution (RCE) vulnerability in Marimo, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-33825, an insufficient granularity of access control vulnerability in Microsoft Defender, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild.
CISA Adds Eight Known Exploited Vulnerabilities to Catalog CISA has added eight actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, affecting various enterprise software including PaperCut, JetBrains TeamCity, Zimbra, and Cisco Catalyst SD-WAN Manager. Organizations are strongly urged to prioritize remediation of these flaws to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-34197, an improper input validation vulnerability in Apache ActiveMQ, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize patching and remediation to reduce their exposure to cyberattacks.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven actively exploited vulnerabilities affecting Microsoft, Adobe, and Fortinet products to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-3502, a vulnerability in TrueConf Client involving the download of code without integrity checks, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to potential cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-5281, a Use-After-Free vulnerability in Google Dawn, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize timely remediation of this vulnerability to reduce exposure to cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two actively exploited vulnerabilities affecting Google Skia (CVE-2026-3909) and Google Chromium V8 (CVE-2026-3910) to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2025-68613, an Improper Control of Dynamically-Managed Code Resources vulnerability in n8n, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize remediation to reduce exposure to cyberattacks.
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three actively exploited vulnerabilities affecting Omnissa Workspace ONE, SolarWinds Web Help Desk, and Ivanti Endpoint Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to apply patches immediately to mitigate the risk of compromise.
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two actively exploited vulnerabilities, CVE-2026-21385 (Qualcomm Memory Corruption) and CVE-2026-22719 (VMware Aria Operations Command Injection), to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these flaws to reduce exposure to cyberattacks.