CISA Adds One Known Exploited Vulnerability to Catalog
2026-05-04T15:24:20Z•a47f16f1c303df710a25e25bebb8780975479187983e2ef26f5533de1fb708c2
BOD-22-01KEVaxioscisaconnectwisecpaneld-linkdetectionincident-responseknown-exploited-vulnerabilitieslinux-kernelmalicious-dependencymarimomicrosoftnpmpatchingremediationremote-access-trojansamsungsimplehelpsupply-chainvulnerability-management
What happened
CISA announced multiple Known Exploited Vulnerabilities (KEV) additions and released a supply‑chain compromise alert. CISA added several CVEs to the KEV catalog (examples: CVE-2026-31431, CVE-2026-41940, CVE-2026-32202, CVE-2026-33825, CVE-2026-39987, CVE-2025-29635 and several 2024 CVEs) and reminded agencies to remediate per Binding Operational Directive (BOD) 22‑01. Separately, CISA warned of a malicious dependency (plain-crypto-js@4.2.1) delivered via compromised axios npm packages (axios@1.14.1 and axios@0.30.4) that downloads multi‑stage payloads including a remote access trojan; CISA’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- a47f16f1c303df710a25e25bebb8780975479187983e2ef26f5533de1fb708c2
- Enrichment time
- 2026-05-04T15:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.