CISA Adds One Known Exploited Vulnerability to Catalog
2026-06-05T19:24:09Z•cc2d94a8a13d848736d079fe9f71071644e366f49d102575a46e3ab25f9d4704
BOD 22-01CI/CDCISAGitHubGitHub ActionsKEV CatalogVSCode extensionexploitationknown-exploited-vulnerabilitiesmalicious-extensionpatchingsupply-chainvulnerability-management
What happened
CISA published multiple KEV Catalog additions (active exploitation) and an advisory on software supply-chain intrusions. New KEV entries cover diverse products including SolarWinds Serv-U, Mirasvit Full Page Cache Warmer, Linux kernel, Android framework, Oracle WebLogic, Palo Alto PAN-OS, Nx Console (malicious VS Code extension), Daemon Tools Lite, TanStack, and LiteSpeed cPanel plugin. CISA also warns of developer-ecosystem supply-chain compromises (malicious Nx Console extension that led to a GitHub compromise and the “Megalodon” campaign injecting malicious GitHub Actions to harvest CI/CD/云
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- cc2d94a8a13d848736d079fe9f71071644e366f49d102575a46e3ab25f9d4704
- Enrichment time
- 2026-06-05T19:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.