CISA Adds One Known Exploited Vulnerability to Catalog
2026-03-19T15:24:20Z•81bf2c9d4d2217e84976b4f7780699a13ae2587d8cc8baf08d406001e7b375b4
BOD 22-01CISAGoogle ChromiumIntune guidanceKEV CatalogMicrosoft SharePointSSRFXSSactive exploitationauthentication bypassdeserializationendpoint managementinformation disclosureremediationvulnerability management
What happened
CISA published multiple alerts in mid‑March 2026 adding several actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog and urging rapid remediation under BOD 22‑01. Newly added CVEs span multiple products and vulnerability types (deserialization of untrusted data, cross‑site scripting, information disclosure, out‑of‑bounds write, authentication bypass, SSRF, etc.). CISA also issued an alert urging organizations to harden endpoint management systems following a March 11, 2026 attack that affected a U.S. organization, recommending least‑privilege RBAC, phishing‑‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 81bf2c9d4d2217e84976b4f7780699a13ae2587d8cc8baf08d406001e7b375b4
- Enrichment time
- 2026-03-19T15:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.