CISA Adds Three Known Exploited Vulnerabilities to Catalog

2026-05-28T03:24:18Z73859aad2cfeb8abdb472709eb36fa12ba2e3752ac58ff3fe189a14f322821ec
BOD-22-01active-exploitationadobe-acrobatbuffer-overflowcisacisco-sd-wandaemon-toolsdirectory-traversaldrupalembedded-malicious-codekevknown-exploited-vulnerabilitieslangflowlitespeedmicrosoft-defendermicrosoft-exchangemicrosoft-windowsnx-consolepatchingprivilege-escalationsql-injectiontanstacktrend-microuse-after-free','cross-site-scriptingvulnerability-management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in May 2026 based on evidence of active exploitation and urged timely remediation under BOD 22-01. Newly listed CVEs affect a range of products including Daemon Tools Lite, TanStack, Nx Console, LiteSpeed cPanel Plugin, Drupal Core, Langflow, Trend Micro Apex One (on‑prem), multiple Microsoft products (Exchange, Defender, Windows/IE), Adobe Acrobat/Reader, and Cisco Catalyst SD‑WAN. Agencies and organizations are strongly encouraged to prioritize patching/mitigation per the KEV/BOD guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
73859aad2cfeb8abdb472709eb36fa12ba2e3752ac58ff3fe189a14f322821ec
Enrichment time
2026-05-28T03:24:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds Three Known Exploited Vulnerabilities to Catalog · Baitaphish