CISA Adds One Known Exploited Vulnerability to Catalog

2026-06-05T19:24:09Zcc2d94a8a13d848736d079fe9f71071644e366f49d102575a46e3ab25f9d4704
BOD 22-01CI/CDCISAGitHubGitHub ActionsKEV CatalogVSCode extensionexploitationknown-exploited-vulnerabilitiesmalicious-extensionpatchingsupply-chainvulnerability-management

What happened

CISA published multiple KEV Catalog additions (active exploitation) and an advisory on software supply-chain intrusions. New KEV entries cover diverse products including SolarWinds Serv-U, Mirasvit Full Page Cache Warmer, Linux kernel, Android framework, Oracle WebLogic, Palo Alto PAN-OS, Nx Console (malicious VS Code extension), Daemon Tools Lite, TanStack, and LiteSpeed cPanel plugin. CISA also warns of developer-ecosystem supply-chain compromises (malicious Nx Console extension that led to a GitHub compromise and the “Megalodon” campaign injecting malicious GitHub Actions to harvest CI/CD/云

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
cc2d94a8a13d848736d079fe9f71071644e366f49d102575a46e3ab25f9d4704
Enrichment time
2026-06-05T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds One Known Exploited Vulnerability to Catalog · Baitaphish