CISA Adds Three Known Exploited Vulnerabilities to Catalog

Summary

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. These include vulnerabilities in Cisco Secure Firewall, Microsoft Windows, and Metabase. The update reinforces CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize remediation of these high-risk vulnerabilities on publicly exposed assets.

IFF Assessment

FOE

The article highlights newly identified and actively exploited vulnerabilities, which represent an increased risk to organizations and require immediate attention from defenders.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating the newly added vulnerabilities from CISA's KEV catalog, especially on publicly facing systems. The inclusion in the KEV catalog signifies active exploitation, meaning threat actors are likely already targeting these flaws. Organizations should also review their vulnerability management processes to ensure alignment with CISA's risk-based approach outlined in BOD 26-04.

Read Full Story →