CISA Adds One Known Exploited Vulnerability to Catalog

2026-05-08T21:24:11Zefee9fa2dee3e52a6563fe83ae67cc75b57e56e8865c74605259837bf5b6a0b9
BOD 22-01KEV Catalogactive_exploitationberriaicisacommand injectionconnectwised-linkimproper input validationivantiknown_exploited_vulnerabilitieslinux kernelmicrosoftmissing authenticationmissing authorizationout-of-bounds writepalo_altopatchingpath traversalsamsungsimplehelpsql injectionvulnerability_managementwebpros

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog (Apr 24 – May 8, 2026) based on evidence of active exploitation. The additions (11 CVEs) span SQL injection, improper input validation, out-of-bounds write, kernel resource-transfer issues, missing authentication/authorization, path traversal, and command injection affecting vendors and products such as BerriAI, Ivanti EPMM, Palo Alto PAN-OS, Linux kernel, WebPros cPanel/WP2, ConnectWise ScreenConnect, Microsoft Windows, Samsung MagicINFO, SimpleHelp, and D‑Link. CISA reiterates BOD 22-01 remediation and,虽

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
efee9fa2dee3e52a6563fe83ae67cc75b57e56e8865c74605259837bf5b6a0b9
Enrichment time
2026-05-08T21:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.