CISA Adds Four Known Exploited Vulnerabilities to Catalog
Summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively being exploited. The article lists specific CVE IDs for vulnerabilities affecting Fortinet, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center. These additions underscore the importance of the KEV Catalog and risk-based vulnerability management for organizations, particularly federal agencies.
IFF Assessment
The addition of actively exploited vulnerabilities to the KEV catalog signifies new threats that defenders must prioritize and mitigate.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should pay close attention to newly added vulnerabilities in the KEV Catalog, as they represent actively exploited threats. Prioritizing patching and remediation for these specific CVEs, especially on publicly exposed assets, is crucial to mitigate immediate risks.