CISA Adds Four Known Exploited Vulnerabilities to Catalog

2026-07-21T23:24:14Z574f3c452c05ed593f948eccbe71be4709327682094134096f8e8c07d89b6d90
BOD 26-04CISACSRFCisco IOSDD-WRTFortinet FortiSandboxKEV CatalogKNXLangflowMicrosoft SharePointOracle E-Business SuiteRCESQL injectionSSRFSonicWall SMA1000WordPressactive exploitationcode injectioncommand injectiondeserializationfile uploadhardeningincident responsepatchingvulnerability management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog during mid‑July 2026 — covering active exploitation across a range of products (WordPress, Microsoft SharePoint, SonicWall SMA1000, Fortinet FortiSandbox, Oracle E‑Business Suite, DD‑WRT, Cisco IOS, KNX, iCagenda, Balbooa Forms, Langflow, and others). CISA highlighted SharePoint RCE/deserialization/exploitation activity, added related SharePoint CVEs to KEV, and reiterated Binding Operational Directive (BOD) 26‑04 requirements for rapid remediation and verification of compromises. Organizations are urgedto

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
574f3c452c05ed593f948eccbe71be4709327682094134096f8e8c07d89b6d90
Enrichment time
2026-07-21T23:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds Four Known Exploited Vulnerabilities to Catalog · Baitaphish