CISA Adds One Known Exploited Vulnerability to Catalog

2026-06-17T15:24:15Zfae914bfc9e46dfaeb0d3c60532ffe13ee997bbc84e8161641cd87e6ff157745
AristaBOD-22-01BOD-26-04BerriAICISACVECheckPointChromiumCiscoIvantiJoomlaKEVLiteSpeedOracleSolarWindsexploitationknown-exploited-vulnerabilitiespatchingvulnerability-management

What happened

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog in June 2026. Newly listed CVEs affect a range of products/vendors including Joomla (Widget Factory), Cisco Catalyst SD‑WAN Manager, LiteSpeed cPanel plugin, Oracle PeopleSoft PeopleTools, Ivanti Sentry OS, Arista EOS, Google Chromium V8, BerriAI LiteLLM, Check Point Security Gateway, SolarWinds Serv‑U, and others. CISA cites evidence of active exploitation and reiterates BOD 22‑01/BOD 26‑04 requirements that federal agencies prioritize rapid remediation and risk‑based vulnerability management for KEV‑list

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
fae914bfc9e46dfaeb0d3c60532ffe13ee997bbc84e8161641cd87e6ff157745
Enrichment time
2026-06-17T15:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.