CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, reinforcing that these issues are being used as real-world attack vectors and should be prioritized for remediation. The newly listed CVEs are CVE-2018-14634 (Linux kernel integer overflow / local privilege escalation), CVE-2025-52691 (SmarterTools SmarterMail unrestricted file upload enabling RCE), CVE-2026-21509 (Microsoft Office security feature bypass), CVE-2026-23760 (SmarterTools SmarterMail authentication bypass via alternate path/channel), and CVE-2026-24061 (GNU InetUtils argument injection). CISA reiterated that these vulnerability classes are frequently leveraged by threat actors and pose material risk to enterprise environments.
Under BOD 22-01, U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed vulnerabilities by CISA-specified due dates, and CISA urged all organizations to treat KEV entries as high-priority items in vulnerability management. Additional technical context highlighted that CVE-2025-52691 can enable unauthenticated arbitrary file upload leading to remote code execution (noted as CVSS 10.0 in the reporting) and that CVE-2018-14634, while older, remains relevant where legacy Linux kernels persist—underscoring that KEV additions can include long-standing flaws when exploitation is observed in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-24858, an authentication bypass using an alternate path or channel affecting multiple Fortinet products, to the Known Exploited Vulnerabilities catalog. The listing indicated evidence of active exploitation and elevated risk to federal networks.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the five newly listed KEV vulnerabilities by February 16, 2026. CISA also urged all organizations to prioritize patching because of evidence of active exploitation.
CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2018-14634, CVE-2025-52691, CVE-2026-23760, CVE-2026-21509, and CVE-2026-24061. The issues affected the Linux kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils.
Microsoft released out-of-band updates for CVE-2026-21509, a Microsoft Office security feature bypass being actively exploited. The company said exploitation required a user to open a malicious Office file and that the Preview Pane was not an attack vector.
Singapore's Cyber Security Agency warned about SmarterTools SmarterMail CVE-2025-52691, describing it as a maximum-severity issue that could enable unauthenticated arbitrary file upload and remote code execution. It recommended upgrading from Build 9406 and earlier to Build 9413.
Qualys disclosed CVE-2018-14634, a Linux kernel integer overflow/local privilege-escalation vulnerability later nicknamed "Mutagen Astronomy." The flaw affected multiple kernel branches and allowed an unprivileged local user to gain root privileges.
A commit on March 19, 2015 introduced the code path that later became CVE-2026-24061 in GNU InetUtils telnetd. The bug enabled argument injection that could lead to authentication bypass and root compromise in affected versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcecisa.gov
Open sourcethecyberthrone.in
Open sourcewindowsforum.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.