Skip to main content
Mallory
Back to intelligence
government-vulnerability-catalogactively-exploited-vulnerabilityembedded-device-vulnerabilitywidely-deployed-product-advisory

CISA Updates Known Exploited Vulnerabilities Catalog With New Entries Including Dell RecoverPoint Hard-Coded Credentials

Updated 3mo agoFirst seen Feb 19, 20262 sources

CISA updated its Known Exploited Vulnerabilities (KEV) Catalog with additional vulnerabilities confirmed as exploited in the wild, reinforcing patch/mitigation urgency under BOD 22-01 timelines. The KEV print catalog shows the addition of CVE-2026-22769 affecting Dell RecoverPoint for Virtual Machines (RP4VMs), described as a use of hard-coded credentials issue that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying OS and establish root-level persistence; CISA’s entry points to Dell advisories/remediation guidance and third-party reporting on active exploitation.

A corresponding update to CISA’s public kev-data repository reflects the routine publication of refreshed KEV data files and includes multiple KEV rows (e.g., CVE-2024-7694 in TeamT5 ThreatSonar Anti-Ransomware for unrestricted file upload leading to command execution with admin privileges on the platform, and legacy items such as CVE-2008-0015 in Microsoft Windows Video ActiveX Control). The KEV print view also lists other exploited items such as CVE-2021-22175 in GitLab (SSRF when internal-network webhook requests are enabled), underscoring that the catalog update spans multiple vendors and vulnerability classes and should be treated as an operational patching priority.

Share:
CISA Updates Known Exploited Vulnerabilities Catalog With New Entries Including Dell RecoverPoint Hard-Coded Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Feb 19, 20264mo ago

CISA publishes updated KEV data files with newly tracked exploited CVEs

A cisagov/kev-data GitHub commit published updated KEV files containing the same set of known exploited vulnerabilities and associated remediation deadlines and references. This represents the public data-file update corresponding to the catalog changes.

Feb 18, 20264mo ago

CISA adds multiple vulnerabilities to the KEV catalog

CISA's Known Exploited Vulnerabilities catalog reflects multiple vulnerabilities as known exploited, including BeyondTrust Remote Support/PRA CVE-2026-1731, Apple CVE-2026-20700, Chromium CVE-2026-2441, Microsoft Configuration Manager CVE-2024-43468, TeamT5 ThreatSonar Anti-Ransomware CVE-2024-7694, Notepad++ CVE-2025-15556, and Windows Video ActiveX CVE-2008-0015. The catalog entry indicates these flaws were formally tracked by CISA for federal remediation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.