CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-05-21T23:24:11Z898020e1fdfea32ea4cd7439e7449e23367e0685cc5ab3e7245fec87487e3eff
AdobeBOD 22-01BerriAICISACiscoIvantiKEVKnown Exploited VulnerabilitiesLangflowMicrosoftPalo Alto NetworksSQL injectionTrend Micro Apex Oneauthentication bypassbuffer overflowcross-site scriptingdenial of servicedirectory traversalelevation of privilegeremediationuse-after-freevulnerability management

What happened

Between 6–21 May 2026, CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Newly listed CVEs cover a range of products and vendors (Microsoft, Adobe, Trend Micro Apex One, Langflow, Cisco, Palo Alto Networks, Ivanti, BerriAI, Ivanti, and others) and include vulnerability types such as buffer overflows, use‑after‑free, SQL injection, directory traversal, authentication bypass, elevation of privilege, cross-site scripting, and denial of service. CISA reiterates remediation requirements under Binding Operational Direc‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
898020e1fdfea32ea4cd7439e7449e23367e0685cc5ab3e7245fec87487e3eff
Enrichment time
2026-05-21T23:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.