CISA Adds One Known Exploited Vulnerability to Catalog

2026-05-22T21:24:16Z530c1ad5f3a30cf6e1ab2134075041696822c4c1d2b2d69b7e6e8cac86c7be72
Apex OneBOD 22-01BerriAICISACiscoDrupalExchangeIvantiKEVKnown-Exploited VulnerabilitiesLangflowMicrosoftSQL injectionTrend Microauthentication bypassbuffer overflowcross-site scriptingdenial of servicedirectory traversalelevation of privilegeimproper input validationvulnerability management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between May 7–22, 2026. The additions include a range of actively exploited issues (SQL injection, authentication bypass, directory traversal, XSS, buffer overflow, elevation-of-privilege, DoS, and improper input validation) affecting products such as Drupal Core, Cisco Catalyst SD‑WAN Controller, Trend Micro Apex One, Microsoft Exchange/Defender, Langflow, BerriAI LiteLLM, Ivanti EPMM, and others. Federal Civilian Executive Branch agencies must remediate listed KEV items per BOD 22‑01; CISA urges all orgs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
530c1ad5f3a30cf6e1ab2134075041696822c4c1d2b2d69b7e6e8cac86c7be72
Enrichment time
2026-05-22T21:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.