CISA Adds Four Known Exploited Vulnerabilities to Catalog

Summary

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively being exploited. The article lists specific CVE IDs for vulnerabilities affecting Fortinet, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center. These additions underscore the importance of the KEV Catalog and risk-based vulnerability management for organizations, particularly federal agencies.

IFF Assessment

FOE

The addition of actively exploited vulnerabilities to the KEV catalog signifies new threats that defenders must prioritize and mitigate.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should pay close attention to newly added vulnerabilities in the KEV Catalog, as they represent actively exploited threats. Prioritizing patching and remediation for these specific CVEs, especially on publicly exposed assets, is crucial to mitigate immediate risks.

Read Full Story →