CISA Adds One Known Exploited Vulnerability to Catalog

2026-07-08T13:24:11Z4e3efc33bfc6689955b3c8c721333a0bf109979ec489b43a941354117846d4e6
Adobe ColdFusionBOD 26-04CISACisco SSRFFortiBleedFortinetJoomShaperJoomlackKEV CatalogLangflowLantronixMFAMicrosoft SharePointPTC WindchillSimpleHelpUbiquiticredential exposurepatchingremediationvulnerability management

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog and issued guidance related to active exploitation and Fortinet credential exposure (FortiBleed). New KEV entries include a range of vulnerabilities (path traversal, deserialization, authentication bypass, SSRF, code injection, improper access control, unrestricted upload, improper input validation, authorization bypass, and improper input validation) across vendors such as Adobe ColdFusion, JoomShaper, Joomlack, Langflow, Microsoft SharePoint Server, SimpleHelp, PTC Windchill/FlexPLM, Cisco Unified CM, Lan0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
4e3efc33bfc6689955b3c8c721333a0bf109979ec489b43a941354117846d4e6
Enrichment time
2026-07-08T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.