CISA Adds One Known Exploited Vulnerability to Catalog
2026-07-01T21:24:14Z•93751222d225edb8c75bf796e8655b6808f35aba36152aefa4b883f8ab563ee7
BOD-26-04Cisco Unified Communications ManagerFlexPLMFortiBleedFortinetJoomlaKEV CatalogLantronix EDS5000Microsoft SharePointPTC WindchillSSRFSimpleHelpSplunk EnterpriseUbiquiti UniFi OSaccess-controlauthentication-bypasscode-injectioncredential-exposuredeserializationimproper-input-validationpath-traversalvulnerability-management
What happened
CISA published multiple alerts in June–July 2026 adding several actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog and urging rapid remediation under Binding Operational Directive (BOD) 26-04. A separate CISA alert urged organizations to harden Fortinet devices after widespread credential exposure (FortiBleed). Affected products include Microsoft SharePoint Server, SimpleHelp, PTC Windchill/FlexPLM, Cisco Unified Communications Manager, Lantronix EDS5000, Ubiquiti UniFi OS, Splunk Enterprise, and a Joomla content editor. CISA emphasizes prioritizing fixes,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 93751222d225edb8c75bf796e8655b6808f35aba36152aefa4b883f8ab563ee7
- Enrichment time
- 2026-07-01T21:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.