CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2021-22175 (a GitLab server-side request forgery (SSRF) issue related to enabling internal-network requests for webhooks) and CVE-2026-22769 (a Dell RecoverPoint for Virtual Machines (RP4VMs) vulnerability involving hard-coded credentials that can enable unauthenticated access to the underlying OS and root-level persistence). Under BOD 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to remediate by CISA’s specified due dates, and CISA urged all organizations to prioritize remediation of KEV-listed issues as part of vulnerability management.
CISA’s public KEV data repository was updated to reflect the new catalog release (catalog count increasing from 1522 to 1524) and to include the new entries with their remediation deadlines (GitLab due 2026-03-11; Dell RP4VMs due 2026-02-21). Separate commentary and guidance from industry media emphasized using KEV as a prioritization input rather than a blanket “panic list,” recommending teams weigh exploitability and impact context (e.g., access prerequisites, remote control potential) and combine KEV with other signals such as CVSS, EPSS, and exploit/tooling intelligence to drive patch sequencing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the newly listed vulnerabilities by specific deadlines. Agencies were ordered to fix the Dell RecoverPoint flaw by 2026-02-21 and the GitLab flaw by 2026-03-11.
On February 18, 2026, CISA added CVE-2021-22175, a GitLab SSRF vulnerability, and CVE-2026-22769, a Dell RecoverPoint for Virtual Machines hard-coded credentials flaw, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The KEV catalog total increased from 1522 to 1524 entries.
Dell released patches and mitigation guidance for the hard-coded credentials flaw CVE-2026-22769 in RecoverPoint for Virtual Machines after receiving reports of limited active exploitation. The fix preceded CISA's later KEV action and federal remediation order.
Google Mandiant reported that suspected PRC-linked cluster UNC6201 had been exploiting Dell RecoverPoint for Virtual Machines vulnerability CVE-2026-22769 since at least mid-2024. The activity involved unauthorized access to VMware backup systems, lateral movement, persistence, and deployment of malware including SLAYSTYLE, BRICKSTORM, and GRIMBOLT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcesecurityaffairs.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.