CISA Adds Three Known Exploited Vulnerabilities to Catalog

2026-07-16T19:24:18Z43f2defca208e22763150afecc03cdd11ee7d790b0386637ad511526cfc78ac7
ADFSBOD-26-04CSRFFortinetKEV CatalogMicrosoft-SharePointRCESSRFSonicWallactive-exploitationcisacommand-injectiondeserializationfile-uploadknown-exploited-vulnerabilitiespatchingvulnerability-managementweb-application

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after observing active exploitation. Affected products include Fortinet FortiSandbox (OS command injection), Microsoft SharePoint (deserialization/RCE and post‑exploitation activity), SonicWall SMA1000 (SSRF and code injection), Microsoft ADFS/AD-related issues, and multiple web plugins/components allowing unsafe file uploads or improper access control; an older Cisco CSRF (CVE-2008-4128) was also added. CISA cites Binding Operational Directive (BOD) 26-04 and urges federal agencies (and all organizations)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
43f2defca208e22763150afecc03cdd11ee7d790b0386637ad511526cfc78ac7
Enrichment time
2026-07-16T19:24:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.