CISA Adds One Known Exploited Vulnerability to Catalog
2026-04-30T19:24:23Z•460fd447b6528024fb6d9101aa0b5d57dc0204f487add3b840929f03bd133461
authentication-bypassaxiosbOD-22-01cisacommand-injectioncredential-rotationkevknown-exploited-vulnerabilitiesmalicious-dependencymitigationnpmnpm-package-compromisepatchingpath-traversalremote-access-trojanremote-code-executionsupply-chainvulnerability-management
What happened
CISA published multiple alerts in April 2026: it added 17 vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog (including issues affecting cPanel/WHM, Microsoft Defender/Windows, Cisco SD‑WAN Manager, PaperCut, JetBrains TeamCity, Samsung MagicINFO, SimpleHelp, D‑Link, Marimo RCE, and others) and released a supply‑chain compromise advisory for the Axios npm package. The Axios compromise (axios@1.14.1 and axios@0.30.4) injected a malicious dependency (plain-crypto-js@4.2.1) that downloads multi‑stage payloads including a remote access trojan; CISA recommends downgrading to axios
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 460fd447b6528024fb6d9101aa0b5d57dc0204f487add3b840929f03bd133461
- Enrichment time
- 2026-04-30T19:24:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.