CISA Adds Four Exploited Vulnerabilities to KEV Catalog, Urging Prioritized Patching
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and urging federal agencies to prioritize remediation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of four new vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). This move signifies that these flaws are not just theoretical weaknesses but are actively being leveraged by malicious actors in the wild, posing a significant and immediate threat.
The newly cataloged vulnerabilities include CVE-2026-33824, a double-free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions; CVE-2026-55040, a weak authentication vulnerability affecting Microsoft SharePoint; CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter; and CVE-2026-65400, an improper authentication vulnerability in Apple macOS.
These types of vulnerabilities are frequently exploited by cybercriminals to gain unauthorized access to systems, disrupt operations, and steal sensitive data. The inclusion in the KEV catalog means that threat intelligence indicates active exploitation, making them high-priority targets for remediation.
CISA's Binding Operational Directive (BOD) 26-04, "Prioritizing Security Updates Based on Risk," mandates that Federal Civilian Executive Branch (FCEB) agencies must prioritize the patching of vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets that offer complete control post-exploitation. This directive underscores the critical importance of the KEV Catalog as a tool for effective vulnerability management.
While BOD 26-04 specifically applies to federal agencies, CISA strongly encourages all organizations, regardless of sector, to adopt a risk-based approach to vulnerability management. Prioritizing the remediation of vulnerabilities identified in the KEV Catalog is a crucial step in bolstering an organization's overall security posture and reducing its attack surface.
The agency also highlighted the importance of checking for signs of compromise before applying patches, a requirement reinforced by BOD 26-04. This proactive measure helps ensure that systems are not only secured but also that any existing breaches are identified and addressed.
CISA remains committed to continuously updating the KEV Catalog as new exploited vulnerabilities are identified. Organizations that become aware of exploited vulnerabilities not yet listed are encouraged to submit them for potential inclusion via CISA's KEV Nomination Form, provided they have a CVE ID, evidence of exploitation, and clear mitigation guidance.
The inclusion of these four vulnerabilities serves as a stark reminder of the dynamic and persistent threat landscape. Proactive vulnerability management and rapid response to known exploited flaws are essential for defending against sophisticated cyberattacks.