CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-07-22T21:24:15Z11cfee0f2335a41c26af4c5ba64f6c57337304aa340785c649b596ffb4c6192e
BOD 26-04CISACisco IOSDD-WRTFortinet FortiSandboxKEV CatalogKNXKnown Exploited VulnerabilitiesMicrosoft SharePointOracle E-Business SuiteSQL injectionSonicWall SMA1000WordPressactive exploitationcode injectiondeserializationpatchingremote code executionserver-side request forgeryvulnerability management

What happened

Between July 14–22, 2026 CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Affected products include Microsoft SharePoint (several deserialization/RCE and missing-authentication issues), SonicWall SMA1000, Fortinet FortiSandbox, WordPress core, Oracle E-Business Suite, DD-WRT, KNX, Cisco IOS, and others. CISA reiterates BOD 26-04 requirements for federal agencies to prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets and urges organizations to adopt risk-based vulnerability management and to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
11cfee0f2335a41c26af4c5ba64f6c57337304aa340785c649b596ffb4c6192e
Enrichment time
2026-07-22T21:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.