CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-06-02T19:24:10Z45a909b6ac0c50ef4d72f432388bbf29bb286f39f56c51605dce5a24cd7add58
BOD 22-01CI/CDCISAGitHubKEV CatalogKnown Exploited VulnerabilitiesMegalodonNx ConsoleVS Code extensionexploitationremediationsupply chainvulnerability management

What happened

CISA published multiple KEV Catalog additions (late May–early June 2026) and an alert about active supply-chain intrusions. New KEV entries include a range of actively exploited flaws — e.g., Linux kernel improper authentication, Android framework integer overflow, Oracle WebLogic unspecified, Palo Alto PAN‑OS authentication bypass, Drupal SQL injection, LiteSpeed cPanel privilege escalation, and several embedded-malicious-code/third‑party library issues. CISA also warned about supply‑chain campaigns: a malicious Nx Console VS Code extension (CVE-2026-48027) that led to a GitHub compromise and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
45a909b6ac0c50ef4d72f432388bbf29bb286f39f56c51605dce5a24cd7add58
Enrichment time
2026-06-02T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.