CISA Adds Five Known Exploited Vulnerabilities to Catalog

2026-03-05T19:24:19Zfa541e87f9af47e891429c370a6e7d7049198b8f90d2e19f5225a81dd55c1fc2
BOD 22-01CISACisco SD-WANED 26-03KEV CatalogSSRFXSSactive exploitationauthentication bypasscommand injectiondeserializationhard-coded credentialsincident responsememory corruptionthreat huntinguse-after-freevulnerability management

What happened

CISA added multiple actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog across vendors including Apple, Cisco, Qualcomm, Broadcom/VMware Aria, Hikvision, Rockwell, Soliton, RoundCube, GitLab, and Dell. Vulnerability types include authentication bypass, command injection, memory corruption, use-after-free, integer overflow, SSRF, deserialization, XSS, and hard-coded credentials; CISA and partners have observed active exploitation (notably ongoing global exploitation of Cisco SD‑WAN) and issued guidance/requirements (including ED 26-03 for Cisco SD‑WAN). BOD 2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
fa541e87f9af47e891429c370a6e7d7049198b8f90d2e19f5225a81dd55c1fc2
Enrichment time
2026-03-05T19:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.