CISA Adds Four Known Exploited Vulnerabilities to Catalog

Summary

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are being actively exploited. These vulnerabilities, affecting DD-WRT and WordPress, are now prioritized for remediation by federal agencies under Binding Operational Directive (BOD) 26-04.

IFF Assessment

FOE

The addition of actively exploited vulnerabilities to a catalog that federal agencies must prioritize for patching indicates increased risk and potential for successful attacks against these systems.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: July 24, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware that these four vulnerabilities are actively being exploited and should prioritize patching them, especially if they are part of publicly exposed assets. The KEV Catalog serves as a critical indicator of immediate threats that require urgent attention.

Read Full Story →