CISA Adds One Known Exploited Vulnerability to Catalog
2026-05-07T17:24:20Z•198ea8b7b824130d4a33e9eae325ba57c783da0f301f6fad48b22752ce313a5f
BOD 22-01CISAConnectWiseD-LinkIvantiKEVKnown Exploited VulnerabilitiesLinux KernelMarimoMicrosoftPalo Alto NetworksSamsungSimpleHelpWebProsactive exploitationcybersecuritypatchingremediationvulnerability management
What happened
CISA announced additions to its Known Exploited Vulnerabilities (KEV) Catalog (late Apr–early May 2026), adding multiple CVEs based on evidence of active exploitation. The alerts reference BOD 22-01 and urge Federal Civilian Executive Branch agencies (and all organizations) to prioritize timely remediation. Affected products/vendors in these additions include Ivanti, Palo Alto Networks (PAN-OS), the Linux kernel, WebPros cPanel/WHM, ConnectWise ScreenConnect, Microsoft Windows, Samsung MagicINFO, SimpleHelp, D-Link, and Marimo.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 198ea8b7b824130d4a33e9eae325ba57c783da0f301f6fad48b22752ce313a5f
- Enrichment time
- 2026-05-07T17:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.