CISA Adds One Known Exploited Vulnerability to Catalog
2026-06-05T13:24:11Z•a625a1f815d257527e84eb3b8b5576f6a9c962a5ed695b9768a6b8ef458298dc
BOD 22-01CI/CDCISAGitHubKEV CatalogMegalodonNx ConsoleSQL injectionVS Codeauthentication bypassdeserializationmalicious extensionpatchingprivilege escalationremediationsupply chainvulnerability management
What happened
CISA alerts (late May–early June 2026) announcing multiple additions to the Known Exploited Vulnerabilities (KEV) Catalog and a supply-chain compromise targeting developer ecosystems. New KEV entries include vulnerabilities affecting Mirasvit, Palo Alto PAN-OS, Oracle WebLogic, Linux kernel, Android framework, Nx Console (malicious VS Code extension), Daemon Tools Lite, TanStack, LiteSpeed cPanel plugin, and Drupal core. CISA also details a supply-chain intrusion where a poisoned Nx Console VS Code extension (CVE-2026-48027) led to unauthorized access and exfiltration of GitHub repositories, +
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- a625a1f815d257527e84eb3b8b5576f6a9c962a5ed695b9768a6b8ef458298dc
- Enrichment time
- 2026-06-05T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.