CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-07-16T17:24:14Z715d69f3cada2daba55cc54cfb1c8820c28bc70ede45d614cc5f150020bfd7a7
Adobe ColdFusionBOD-26-04CISACSRFCisco IOSKEV CatalogOracle E-Business SuiteRCESharePointSonicWallcode injectionexploitpatchingpath traversalprivilege managementremediationserver-side request forgeryunrestricted file uploadvulnerability management

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog and issued guidance urging rapid, prioritized remediation per Binding Operational Directive (BOD) 26-04. Newly listed and actively exploited CVEs affect a range of products including Microsoft SharePoint/ADFS, SonicWall SMA1000, Oracle E-Business Suite, Adobe ColdFusion, Cisco IOS, KNX protocol implementations, multiple web builders/plugins (JoomShaper, Joomlack, iCagenda, Balbooa), and others. CISA highlighted active SharePoint exploitations (RCE and post-exploitation actions), recommended immediate patch/‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
715d69f3cada2daba55cc54cfb1c8820c28bc70ede45d614cc5f150020bfd7a7
Enrichment time
2026-07-16T17:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds Two Known Exploited Vulnerabilities to Catalog · Baitaphish