CISA Adds One Known Exploited Vulnerability to Catalog
2026-05-22T21:24:16Z•530c1ad5f3a30cf6e1ab2134075041696822c4c1d2b2d69b7e6e8cac86c7be72
Apex OneBOD 22-01BerriAICISACiscoDrupalExchangeIvantiKEVKnown-Exploited VulnerabilitiesLangflowMicrosoftSQL injectionTrend Microauthentication bypassbuffer overflowcross-site scriptingdenial of servicedirectory traversalelevation of privilegeimproper input validationvulnerability management
What happened
CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog between May 7–22, 2026. The additions include a range of actively exploited issues (SQL injection, authentication bypass, directory traversal, XSS, buffer overflow, elevation-of-privilege, DoS, and improper input validation) affecting products such as Drupal Core, Cisco Catalyst SD‑WAN Controller, Trend Micro Apex One, Microsoft Exchange/Defender, Langflow, BerriAI LiteLLM, Ivanti EPMM, and others. Federal Civilian Executive Branch agencies must remediate listed KEV items per BOD 22‑01; CISA urges all orgs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 530c1ad5f3a30cf6e1ab2134075041696822c4c1d2b2d69b7e6e8cac86c7be72
- Enrichment time
- 2026-05-22T21:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.