CISA Adds Three Known Exploited Vulnerabilities to Catalog
2026-07-16T19:24:18Z•43f2defca208e22763150afecc03cdd11ee7d790b0386637ad511526cfc78ac7
ADFSBOD-26-04CSRFFortinetKEV CatalogMicrosoft-SharePointRCESSRFSonicWallactive-exploitationcisacommand-injectiondeserializationfile-uploadknown-exploited-vulnerabilitiespatchingvulnerability-managementweb-application
What happened
CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after observing active exploitation. Affected products include Fortinet FortiSandbox (OS command injection), Microsoft SharePoint (deserialization/RCE and post‑exploitation activity), SonicWall SMA1000 (SSRF and code injection), Microsoft ADFS/AD-related issues, and multiple web plugins/components allowing unsafe file uploads or improper access control; an older Cisco CSRF (CVE-2008-4128) was also added. CISA cites Binding Operational Directive (BOD) 26-04 and urges federal agencies (and all organizations)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 43f2defca208e22763150afecc03cdd11ee7d790b0386637ad511526cfc78ac7
- Enrichment time
- 2026-07-16T19:24:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.