CISA Adds Four Known Exploited Vulnerabilities to Catalog
Summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are being actively exploited. These vulnerabilities, affecting DD-WRT and WordPress, are now prioritized for remediation by federal agencies under Binding Operational Directive (BOD) 26-04.
IFF Assessment
The addition of actively exploited vulnerabilities to a catalog that federal agencies must prioritize for patching indicates increased risk and potential for successful attacks against these systems.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: July 24, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should be aware that these four vulnerabilities are actively being exploited and should prioritize patching them, especially if they are part of publicly exposed assets. The KEV Catalog serves as a critical indicator of immediate threats that require urgent attention.