CISA Adds Three Known Exploited Vulnerabilities to Catalog

2026-07-07T19:24:05Zf82760095988358143a370d7a3e3009e9030793171da4abc9998121ecc2a211e
BOD-26-04CISAFortiBleedFortinetKEV CatalogMFAPBKDF2SSRFauthentication-bypasscredential-exposureknown-exploited-vulnerabilitypatchingremediationvulnerability

What happened

CISA announced multiple additions to its Known Exploited Vulnerabilities (KEV) Catalog and issued guidance on Fortinet credential exposure (FortiBleed). New KEV entries include vulnerabilities in JoomShaper SP Page Builder, Langflow, Joomlack Page Builder, Microsoft SharePoint Server, SimpleHelp, PTC Windchill/FlexPLM, Cisco Unified Communications Manager (SSRF), Lantronix EDS5000, Ubiquiti UniFi OS (multiple issues), and Splunk Enterprise. CISA reiterated BOD 26-04 requirements to prioritize rapid remediation of KEV-listed flaws on publicly exposed assets and provided Fortinet mitigation and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
f82760095988358143a370d7a3e3009e9030793171da4abc9998121ecc2a211e
Enrichment time
2026-07-07T19:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.