CISA Adds One Known Exploited Vulnerability to Catalog
2026-07-08T13:24:11Z•4e3efc33bfc6689955b3c8c721333a0bf109979ec489b43a941354117846d4e6
Adobe ColdFusionBOD 26-04CISACisco SSRFFortiBleedFortinetJoomShaperJoomlackKEV CatalogLangflowLantronixMFAMicrosoft SharePointPTC WindchillSimpleHelpUbiquiticredential exposurepatchingremediationvulnerability management
What happened
CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog and issued guidance related to active exploitation and Fortinet credential exposure (FortiBleed). New KEV entries include a range of vulnerabilities (path traversal, deserialization, authentication bypass, SSRF, code injection, improper access control, unrestricted upload, improper input validation, authorization bypass, and improper input validation) across vendors such as Adobe ColdFusion, JoomShaper, Joomlack, Langflow, Microsoft SharePoint Server, SimpleHelp, PTC Windchill/FlexPLM, Cisco Unified CM, Lan0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 4e3efc33bfc6689955b3c8c721333a0bf109979ec489b43a941354117846d4e6
- Enrichment time
- 2026-07-08T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.