• CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    From CISA Advisories@2:263/1 to All on Mon Apr 13 19:11:06 2026
    CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

    CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
    CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability
    CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
    CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability CVE-2025-60710 Microsoft Windows Link Following Vulnerability
    CVE-2026-21643 Fortinet SQL Injection Vulnerability
    CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability

    These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
    Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
    Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

    https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    2026-04-13 12:00 UTC
    --- FMail-lnx 2.3.2.6-B20251227
    * Origin: TCOB1 A Mail Only System (2:263/1)
  • From CISA Advisories@2:263/1 to All on Wed May 20 19:11:06 2026
    CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

    CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability
    CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability
    CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability

    These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
    Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
    Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

    https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    2026-05-20 12:00 UTC
    --- FMail-lnx 2.3.2.6-B20251227
    * Origin: TCOB1 A Mail Only System (2:263/1)
  • From Cisa Advisories@2:263/1 to All on Wed Sep 2 18:33:06 2026
    CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.


    CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability




    CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability




    CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability




    CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability




    CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability




    CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability




    CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.


    Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of
    high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA?s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.


    While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.


    Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA?s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear
    mitigation guidance.

    https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploi ted-vulnerabilities-catalog

    2026-09-02 12:00 UTC

    --- BBBS/LiR v4.10 Toy-7
    * Origin: LISTS. from TCOB1 READ ONLY (2:263/1)