CISA Adds One Known Exploited Vulnerability to Catalog

2026-04-30T19:24:23Z460fd447b6528024fb6d9101aa0b5d57dc0204f487add3b840929f03bd133461
authentication-bypassaxiosbOD-22-01cisacommand-injectioncredential-rotationkevknown-exploited-vulnerabilitiesmalicious-dependencymitigationnpmnpm-package-compromisepatchingpath-traversalremote-access-trojanremote-code-executionsupply-chainvulnerability-management

What happened

CISA published multiple alerts in April 2026: it added 17 vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog (including issues affecting cPanel/WHM, Microsoft Defender/Windows, Cisco SD‑WAN Manager, PaperCut, JetBrains TeamCity, Samsung MagicINFO, SimpleHelp, D‑Link, Marimo RCE, and others) and released a supply‑chain compromise advisory for the Axios npm package. The Axios compromise (axios@1.14.1 and axios@0.30.4) injected a malicious dependency (plain-crypto-js@4.2.1) that downloads multi‑stage payloads including a remote access trojan; CISA recommends downgrading to axios

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
460fd447b6528024fb6d9101aa0b5d57dc0204f487add3b840929f03bd133461
Enrichment time
2026-04-30T19:24:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.