CISA Adds One Known Exploited Vulnerability to Catalog
2026-04-23T19:24:26Z•699023b7caa8f1471ae58e5b80212bac8873ae3a70e6ea9a4368f39746129c99
AdobeApache-ActiveMQAxiosBOD-22-01CISACiscoFortinetJetBrainsKEVKenticoKnown-Exploited-VulnerabilitiesMicrosoftMicrosoft-ExchangePaperCutQuest-KACERATSynacorcredential-theftnpmplain-crypto-jsremote-access-trojanremote-code-executionsupply-chainsupply-chain-compromise
What happened
CISA published multiple alerts in April 2026 adding numerous actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog and releasing an alert about a software supply-chain compromise. Between 14–23 Apr 2026 CISA added over a dozen KEV entries (vendors affected include Microsoft, Apache ActiveMQ, PaperCut, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra, Cisco Catalyst SD‑WAN Manager, Fortinet, Adobe, Microsoft Exchange/Windows, and others). Separately, CISA warns of a supply‑chain compromise of the Axios npm package: axios@1.14.1 and axios@0.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 699023b7caa8f1471ae58e5b80212bac8873ae3a70e6ea9a4368f39746129c99
- Enrichment time
- 2026-04-23T19:24:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.