CISA Adds Four Known Exploited Vulnerabilities to Catalog
2026-07-21T23:24:14Z•574f3c452c05ed593f948eccbe71be4709327682094134096f8e8c07d89b6d90
BOD 26-04CISACSRFCisco IOSDD-WRTFortinet FortiSandboxKEV CatalogKNXLangflowMicrosoft SharePointOracle E-Business SuiteRCESQL injectionSSRFSonicWall SMA1000WordPressactive exploitationcode injectioncommand injectiondeserializationfile uploadhardeningincident responsepatchingvulnerability management
What happened
CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog during mid‑July 2026 — covering active exploitation across a range of products (WordPress, Microsoft SharePoint, SonicWall SMA1000, Fortinet FortiSandbox, Oracle E‑Business Suite, DD‑WRT, Cisco IOS, KNX, iCagenda, Balbooa Forms, Langflow, and others). CISA highlighted SharePoint RCE/deserialization/exploitation activity, added related SharePoint CVEs to KEV, and reiterated Binding Operational Directive (BOD) 26‑04 requirements for rapid remediation and verification of compromises. Organizations are urgedto
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 574f3c452c05ed593f948eccbe71be4709327682094134096f8e8c07d89b6d90
- Enrichment time
- 2026-07-21T23:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.