CISA Adds One Known Exploited Vulnerability to Catalog

2026-05-04T15:24:20Za47f16f1c303df710a25e25bebb8780975479187983e2ef26f5533de1fb708c2
BOD-22-01KEVaxioscisaconnectwisecpaneld-linkdetectionincident-responseknown-exploited-vulnerabilitieslinux-kernelmalicious-dependencymarimomicrosoftnpmpatchingremediationremote-access-trojansamsungsimplehelpsupply-chainvulnerability-management

What happened

CISA announced multiple Known Exploited Vulnerabilities (KEV) additions and released a supply‑chain compromise alert. CISA added several CVEs to the KEV catalog (examples: CVE-2026-31431, CVE-2026-41940, CVE-2026-32202, CVE-2026-33825, CVE-2026-39987, CVE-2025-29635 and several 2024 CVEs) and reminded agencies to remediate per Binding Operational Directive (BOD) 22‑01. Separately, CISA warned of a malicious dependency (plain-crypto-js@4.2.1) delivered via compromised axios npm packages (axios@1.14.1 and axios@0.30.4) that downloads multi‑stage payloads including a remote access trojan; CISA’s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
a47f16f1c303df710a25e25bebb8780975479187983e2ef26f5533de1fb708c2
Enrichment time
2026-05-04T15:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.