CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-07-15T19:24:12Z02f23ee6dc870ab7bfbd7ab11c5826922798d1748ab390240a75f618379b87ab
Adobe ColdFusionBOD-26-04CISACisco IOSKEV CatalogKNXMicrosoft ADFSMicrosoft SharePointOracle E-Business SuiteSonicWall SMA1000code-injectionexploitpath-traversalprivilege-escalationremediationserver-side-request-forgeryunrestricted-file-uploadvulnerability-management

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog based on observed active exploitation. Affected products/vendors include Microsoft SharePoint and ADFS, SonicWall SMA1000, Oracle E-Business Suite, KNX protocol implementations, Cisco IOS, Adobe ColdFusion, and multiple web plugins/components (iCagenda, Balbooa Forms, JoomShaper, Joomlack, Langflow). CISA reiterates BOD 26-04 guidance to prioritize rapid remediation and investigation of KEV-listed vulnerabilities on publicly exposed assets.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
02f23ee6dc870ab7bfbd7ab11c5826922798d1748ab390240a75f618379b87ab
Enrichment time
2026-07-15T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.