CISA Adds One Known Exploited Vulnerability to Catalog

2026-06-03T19:24:04Z62b1ce2d73b49a00536caccd6ac0b88d64eaaca218b0b52a6941c98d1d4d182a
BOD 22-01CI/CDCISAGitHubKEV CatalogMegalodon campaignNx ConsoleVS Code extensionauthentication-bypassdeserializationembedded-malicious-codeknown-exploited-vulnerabilitiesprivilege-escalationsql-injectionsupply-chain-compromisevulnerability-management

What happened

CISA published multiple KEV Catalog additions and an alert on supply-chain compromises. Over late May–early June 2026 CISA added several actively exploited CVEs to its Known Exploited Vulnerabilities (KEV) Catalog and reminded organizations to remediate per BOD 22-01. Newly listed CVEs include vulnerabilities such as deserialization of untrusted data, authentication bypass, integer overflow, SQL injection, privilege escalation, and embedded malicious code. Separately, CISA reported supply-chain intrusions affecting developer ecosystems: a malicious Nx Console VS Code extension (CVE-2026-48027)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
62b1ce2d73b49a00536caccd6ac0b88d64eaaca218b0b52a6941c98d1d4d182a
Enrichment time
2026-06-03T19:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.