CISA Adds One Known Exploited Vulnerability to Catalog
2026-05-08T21:24:11Z•efee9fa2dee3e52a6563fe83ae67cc75b57e56e8865c74605259837bf5b6a0b9
BOD 22-01KEV Catalogactive_exploitationberriaicisacommand injectionconnectwised-linkimproper input validationivantiknown_exploited_vulnerabilitieslinux kernelmicrosoftmissing authenticationmissing authorizationout-of-bounds writepalo_altopatchingpath traversalsamsungsimplehelpsql injectionvulnerability_managementwebpros
What happened
CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog (Apr 24 – May 8, 2026) based on evidence of active exploitation. The additions (11 CVEs) span SQL injection, improper input validation, out-of-bounds write, kernel resource-transfer issues, missing authentication/authorization, path traversal, and command injection affecting vendors and products such as BerriAI, Ivanti EPMM, Palo Alto PAN-OS, Linux kernel, WebPros cPanel/WP2, ConnectWise ScreenConnect, Microsoft Windows, Samsung MagicINFO, SimpleHelp, and D‑Link. CISA reiterates BOD 22-01 remediation and,虽
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- efee9fa2dee3e52a6563fe83ae67cc75b57e56e8865c74605259837bf5b6a0b9
- Enrichment time
- 2026-05-08T21:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.