CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

2026-04-25T07:24:08Z4d8e21b6b77cfe41f81b8234ce0c1fccd7943663ea17b0c522bab0e0d526ced5
ASP.NET CoreApple iOSBitwardenCISACVE-2024-57726CVE-2026-28950CVE-2026-33626CVE-2026-40372CVE-2026-5752CanisterSprawlCheckmarxCisco FirepowerCohereFIRESTARTERKICSKnown Exploited VulnerabilitiesLMDeploySSRFTerrariumUNC6692','Tropic Trooper','Lotus Wiper','SystemBC','Vercelbackdoormalwarephishingsandbox-escapesupply chain

What happened

A cluster of high-impact incidents and active exploitations was reported across federal and commercial environments. CISA added four actively exploited flaws to its KEV list (notably CVE-2024-57726, CVSS 9.9) and set a May 2026 federal mitigation deadline. Multiple supply‑chain compromises and rapid post‑disclosure exploits were observed — including the Bitwarden CLI compromise (malicious bw1.js) tied to a Checkmarx campaign, malicious Checkmarx/KICS Docker tags, the CanisterSprawl npm worm, and LMDeploy’s SSRF (CVE-2026-33626) which was exploited within 13 hours. Severe product flaws and intr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4d8e21b6b77cfe41f81b8234ce0c1fccd7943663ea17b0c522bab0e0d526ced5
Enrichment time
2026-04-25T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.