CISA Adds One Known Exploited Vulnerability to Catalog

2026-05-01T21:24:19Z90476c73c8b42c066f05d0743400c4446640e7b37e6f1947c5bae8a5742e8504
axioscisaconnectwisecpaneld-linkkev-catalogknown-exploited-vulnerabilitieslinux-kernelnpm-supply-chainplain-crypto-jsremote-access-trojansamsungsimplehelpvulnerability-managementwebappswindows

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog in late April–May 2026 and released an alert on a separate npm supply-chain compromise. Newly listed CVEs (active exploitation evidence) include: CVE-2026-31431 (Linux kernel), CVE-2026-41940 (WebPros cPanel & WHM / WP2 missing auth), CVE-2024-1708 (ConnectWise ScreenConnect path traversal), CVE-2026-32202 (Microsoft Windows protection mechanism failure), CVE-2024-7399 (Samsung MagicINFO path traversal), CVE-2024-57726 and CVE-2024-57728 (SimpleHelp auth/path traversal), CVE-2025-29635 (D-Link DIR-823X cmdi)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
90476c73c8b42c066f05d0743400c4446640e7b37e6f1947c5bae8a5742e8504
Enrichment time
2026-05-01T21:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds One Known Exploited Vulnerability to Catalog · Baitaphish