CISA Adds One Known Exploited Vulnerability to Catalog

2026-08-17T15:24:03Zdd2fde49515d0d23f13186432260d749a09126518655835a2812d567701056e4
CVE-2025-62593CVE-2026-18556CVE-2026-18577CVE-2026-20349CVE-2026-34486CVE-2026-63077CVE-2026-68820CVE-2026-72898CVE-2026-8037CVE-2026-9198CISAKEVKnown Exploited VulnerabilitiesOT securityPLCsSQL injectionactive exploitationauthentication bypasscode injectioncommand injectioncritical infrastructureindustrial control systemsinternet-exposed assetsunsafe deserializationuse-after-freevulnerability managementwater and wastewater systems

What happened

CISA reports active exploitation of multiple vulnerabilities added to the Known Exploited Vulnerabilities (KEV) Catalog, including code injection, heap inspection, use-after-free, SQL injection, command injection, unsafe deserialization, authentication bypass, and sensitive-data encryption weaknesses affecting Ray, Cisco ASA/FTD, Microsoft Windows, Metabase, Progress LoadMaster, JetBrains TeamCity, IBM Langflow, N-able N-central, and Apache Tomcat. CISA also warns that threat actors are targeting internet-exposed programmable logic controllers in the Water and Wastewater Systems sector, with a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
dd2fde49515d0d23f13186432260d749a09126518655835a2812d567701056e4
Enrichment time
2026-08-17T15:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.