CISA Adds One Known Exploited Vulnerability to Catalog
2026-05-01T21:24:19Z•90476c73c8b42c066f05d0743400c4446640e7b37e6f1947c5bae8a5742e8504
axioscisaconnectwisecpaneld-linkkev-catalogknown-exploited-vulnerabilitieslinux-kernelnpm-supply-chainplain-crypto-jsremote-access-trojansamsungsimplehelpvulnerability-managementwebappswindows
What happened
CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog in late April–May 2026 and released an alert on a separate npm supply-chain compromise. Newly listed CVEs (active exploitation evidence) include: CVE-2026-31431 (Linux kernel), CVE-2026-41940 (WebPros cPanel & WHM / WP2 missing auth), CVE-2024-1708 (ConnectWise ScreenConnect path traversal), CVE-2026-32202 (Microsoft Windows protection mechanism failure), CVE-2024-7399 (Samsung MagicINFO path traversal), CVE-2024-57726 and CVE-2024-57728 (SimpleHelp auth/path traversal), CVE-2025-29635 (D-Link DIR-823X cmdi)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 90476c73c8b42c066f05d0743400c4446640e7b37e6f1947c5bae8a5742e8504
- Enrichment time
- 2026-05-01T21:24:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.