CISA Adds One Known Exploited Vulnerability to Catalog

2026-05-07T17:24:20Z198ea8b7b824130d4a33e9eae325ba57c783da0f301f6fad48b22752ce313a5f
BOD 22-01CISAConnectWiseD-LinkIvantiKEVKnown Exploited VulnerabilitiesLinux KernelMarimoMicrosoftPalo Alto NetworksSamsungSimpleHelpWebProsactive exploitationcybersecuritypatchingremediationvulnerability management

What happened

CISA announced additions to its Known Exploited Vulnerabilities (KEV) Catalog (late Apr–early May 2026), adding multiple CVEs based on evidence of active exploitation. The alerts reference BOD 22-01 and urge Federal Civilian Executive Branch agencies (and all organizations) to prioritize timely remediation. Affected products/vendors in these additions include Ivanti, Palo Alto Networks (PAN-OS), the Linux kernel, WebPros cPanel/WHM, ConnectWise ScreenConnect, Microsoft Windows, Samsung MagicINFO, SimpleHelp, D-Link, and Marimo.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
198ea8b7b824130d4a33e9eae325ba57c783da0f301f6fad48b22752ce313a5f
Enrichment time
2026-05-07T17:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds One Known Exploited Vulnerability to Catalog · Baitaphish