CISA Adds One Known Exploited Vulnerability to Catalog

2026-08-03T21:24:04Z08d608e5698969aca67d5e0fa9b611d6dd6dc4f465a8130df8f6001923ed129d
CVE-2021-27137CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-18577CVE-2026-20316CVE-2026-25089CVE-2026-39808CVE-2026-50522CVE-2026-58644CVE-2026-60137CVE-2026-63030CISAKEVKnown Exploited VulnerabilitiesOT securityPLCsSQL injectionactive exploitationauthentication bypassbuffer overflowcommand injectioncritical infrastructuredeserializationhard-coded passwordinternet-exposed assetsoperational technologyvulnerability managementwater and wastewater

What happened

CISA reports active exploitation of multiple vulnerabilities added to the Known Exploited Vulnerabilities Catalog, including authentication bypass, hard-coded credentials, sensitive information exposure, command injection, deserialization, SQL injection, buffer overflow, and improper authentication flaws affecting enterprise, security, networking, collaboration, and web platforms. CISA also warns that threat actors are targeting internet-exposed programmable logic controllers in the water and wastewater sector, modifying passwords and IP addresses to lock out operators and disrupt operations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
08d608e5698969aca67d5e0fa9b611d6dd6dc4f465a8130df8f6001923ed129d
Enrichment time
2026-08-03T21:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.