CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-07-22T21:24:15Z•11cfee0f2335a41c26af4c5ba64f6c57337304aa340785c649b596ffb4c6192e
BOD 26-04CISACisco IOSDD-WRTFortinet FortiSandboxKEV CatalogKNXKnown Exploited VulnerabilitiesMicrosoft SharePointOracle E-Business SuiteSQL injectionSonicWall SMA1000WordPressactive exploitationcode injectiondeserializationpatchingremote code executionserver-side request forgeryvulnerability management
What happened
Between July 14–22, 2026 CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Affected products include Microsoft SharePoint (several deserialization/RCE and missing-authentication issues), SonicWall SMA1000, Fortinet FortiSandbox, WordPress core, Oracle E-Business Suite, DD-WRT, KNX, Cisco IOS, and others. CISA reiterates BOD 26-04 requirements for federal agencies to prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets and urges organizations to adopt risk-based vulnerability management and to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 11cfee0f2335a41c26af4c5ba64f6c57337304aa340785c649b596ffb4c6192e
- Enrichment time
- 2026-07-22T21:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.