CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-06-25T23:24:12Z•8abbaed456584e4a44c9e5c3b6eeabddebe7c5b4ccaf4a08fd014107f221b2d1
BOD 26-04CISAFederal guidanceFortiBleedFortinetKnown Exploited Vulnerabilities (KEV)SSRFcode injectioncredential exposureimproper access controlimproper input validationmissing authenticationpath traversalsymlinkvulnerability management
What happened
CISA posted multiple Alerts in June 2026 adding a series of actively exploited CVEs to its Known Exploited Vulnerabilities (KEV) Catalog and issuing guidance on a widespread Fortinet credential exposure (FortiBleed). Affected products include PTC Windchill/FlexPLM, Cisco UC Manager, Lantronix EDS5000, Ubiquiti UniFi OS, Splunk Enterprise, Joomla plugin, Cisco Catalyst SD‑WAN Manager, LiteSpeed cPanel plugin, Oracle PeopleSoft, and others. CISA reiterates BOD 26‑04 requirements for rapid remediation of KEV-listed vulnerabilities on public-facing assets and urges organizations to follow vendor/C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 8abbaed456584e4a44c9e5c3b6eeabddebe7c5b4ccaf4a08fd014107f221b2d1
- Enrichment time
- 2026-06-25T23:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.