CISA Adds One Known Exploited Vulnerability to Catalog

2026-06-01T19:24:15Z05d88850cf96e75e5912505e65fa2dff76bef4b401076ced3b9b99d453e56975
BOD 22-01CI/CDCISACVEDaemon ToolsDrupalGitHubKEV CatalogLangflowLiteSpeedMegalodonNx ConsoleOracle WebLogicPAN-OSSQL injectionTanStackTrend Micro Apex OneVS Code extensionauthentication bypassdirectory traversalmalicious codeprivilege escalationsupply chainvulnerability

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog and published an alert on software supply chain intrusions. Newly cataloged CVEs include vulnerabilities affecting Oracle WebLogic (CVE-2024-21182), Palo Alto PAN-OS authentication bypass (CVE-2026-0257), Nx Console malicious VS Code extension (CVE-2026-48027), Daemon Tools Lite (CVE-2026-8398), TanStack (CVE-2026-45321), LiteSpeed cPanel plugin privilege escalation (CVE-2026-48172), Drupal Core SQL injection (CVE-2026-9082), Langflow origin validation error (CVE-2025-34291), and Trend Micro Apex One on-prem

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
05d88850cf96e75e5912505e65fa2dff76bef4b401076ced3b9b99d453e56975
Enrichment time
2026-06-01T19:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds One Known Exploited Vulnerability to Catalog · Baitaphish