CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-06-02T19:24:10Z•45a909b6ac0c50ef4d72f432388bbf29bb286f39f56c51605dce5a24cd7add58
BOD 22-01CI/CDCISAGitHubKEV CatalogKnown Exploited VulnerabilitiesMegalodonNx ConsoleVS Code extensionexploitationremediationsupply chainvulnerability management
What happened
CISA published multiple KEV Catalog additions (late May–early June 2026) and an alert about active supply-chain intrusions. New KEV entries include a range of actively exploited flaws — e.g., Linux kernel improper authentication, Android framework integer overflow, Oracle WebLogic unspecified, Palo Alto PAN‑OS authentication bypass, Drupal SQL injection, LiteSpeed cPanel privilege escalation, and several embedded-malicious-code/third‑party library issues. CISA also warned about supply‑chain campaigns: a malicious Nx Console VS Code extension (CVE-2026-48027) that led to a GitHub compromise and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 45a909b6ac0c50ef4d72f432388bbf29bb286f39f56c51605dce5a24cd7add58
- Enrichment time
- 2026-06-02T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.