CISA Adds One Known Exploited Vulnerability to Catalog
2026-08-03T21:24:04Z•08d608e5698969aca67d5e0fa9b611d6dd6dc4f465a8130df8f6001923ed129d
CVE-2021-27137CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-18577CVE-2026-20316CVE-2026-25089CVE-2026-39808CVE-2026-50522CVE-2026-58644CVE-2026-60137CVE-2026-63030CISAKEVKnown Exploited VulnerabilitiesOT securityPLCsSQL injectionactive exploitationauthentication bypassbuffer overflowcommand injectioncritical infrastructuredeserializationhard-coded passwordinternet-exposed assetsoperational technologyvulnerability managementwater and wastewater
What happened
CISA reports active exploitation of multiple vulnerabilities added to the Known Exploited Vulnerabilities Catalog, including authentication bypass, hard-coded credentials, sensitive information exposure, command injection, deserialization, SQL injection, buffer overflow, and improper authentication flaws affecting enterprise, security, networking, collaboration, and web platforms. CISA also warns that threat actors are targeting internet-exposed programmable logic controllers in the water and wastewater sector, modifying passwords and IP addresses to lock out operators and disrupt operations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 08d608e5698969aca67d5e0fa9b611d6dd6dc4f465a8130df8f6001923ed129d
- Enrichment time
- 2026-08-03T21:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.