CISA repeatedly expanded its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation across a wide range of products, including Apple platforms, Ivanti EPM and EPMM, SolarWinds Web Help Desk, Omnissa Workspace ONE, n8n, Google Chromium and Skia, Wing FTP Server, Zimbra, Cisco firewall management products, Langflow, Aqua Security Trivy, F5 BIG-IP, Fortinet FortiClient EMS, Microsoft Exchange, SharePoint, Windows, Defender, Adobe Acrobat/Reader, Apache ActiveMQ, Trend Micro Apex One, Palo Alto PAN-OS, and other enterprise software. Several entries were especially notable because they involved remote code execution, code injection, deserialization, authentication bypass, privilege escalation, and supply-chain-style malicious code risks, while CISA also highlighted active exploitation of older legacy Microsoft and Adobe flaws that remain dangerous on unpatched or end-of-life systems.
Reporting tied some of the newly listed issues to concrete attack activity and elevated operational risk. Apple flaws added to KEV were reported as exploitable through malicious web content or apps and could lead to arbitrary code execution or kernel-level execution, while the critical Langflow bug CVE-2025-34291 was described as enabling session hijacking, token theft, persistence, and possible full system compromise in AI workflow deployments; separate reporting said the Iranian threat actor MuddyWater used it for initial access. Trend Micro said it observed at least one attempted in-the-wild exploitation of its Apex One flaw, and coverage of Ivanti vulnerabilities warned that defenders should not rely solely on shared indicators of compromise. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were ordered to remediate each KEV-listed flaw by assigned deadlines, and CISA urged all organizations to apply vendor fixes or mitigations immediately and discontinue affected products if no mitigation is available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
34 events from the most recent confirmed update back to the earliest known activity.
On June 29, 2026, CISA added CVE-2026-48558, an authentication bypass vulnerability affecting SimpleHelp, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. CISA warned that this class of flaw is a frequent attack vector and directed federal agencies to prioritize remediation under Binding Operational Directive 26-04.
On 2026-06-23, CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog: CVE-2025-67038 affecting Lantronix EDS5000 and CVE-2026-34910, CVE-2026-34909, and CVE-2026-34908 affecting Ubiquiti UniFi OS. The flaws included code injection, command injection, path traversal, and improper access control issues, all listed as actively exploited.
On June 16, 2026, CISA added CVE-2026-48907, an improper access control vulnerability affecting the Widget Factory Joomla Content Editor, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
On June 15, 2026, CISA added CVE-2026-20262, a Cisco Catalyst SD-WAN Manager directory or path traversal vulnerability, and CVE-2026-54420, a LiteSpeed cPanel Plugin UNIX symbolic link following vulnerability, to the Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation.
On June 9, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-7473 in Arista Extensible Operating System, CVE-2026-11645 in Google Chromium V8, and CVE-2026-20245 in Cisco Catalyst SD-WAN Manager. CISA said the additions were based on evidence of active exploitation and urged organizations to prioritize remediation.
On May 29, 2026, CISA added CVE-2026-0257, an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS, to the KEV catalog based on evidence of active exploitation.
On May 26, 2026, CISA added CVE-2026-48172, a LiteSpeed cPanel Plugin privilege escalation vulnerability, to the KEV catalog after determining there was evidence of active exploitation.
In March 2026, Ctrl-Alt-Intel reported that the Iranian threat actor MuddyWater exploited Langflow vulnerability CVE-2025-34291 for initial access. This linked a specific threat actor to real-world exploitation of the flaw later added to CISA's KEV catalog.
On May 21, 2026, CISA added CVE-2025-34291, a Langflow origin validation error vulnerability, and CVE-2026-34926, a Trend Micro Apex One on-premise directory traversal vulnerability, to the KEV catalog after determining there was evidence of active exploitation. Multiple reports noted the Langflow flaw could enable session hijacking, token theft, and potentially arbitrary code execution, while Trend Micro said it had observed at least one attempted in-the-wild exploitation of the Apex One issue.
On May 20, 2026, CISA added seven actively exploited vulnerabilities affecting Microsoft Windows, Microsoft DirectX, Adobe Acrobat and Reader, Microsoft Internet Explorer, and Microsoft Defender to the KEV catalog. The set included legacy flaws from 2008 through 2010 as well as two 2026 Microsoft Defender vulnerabilities.
On May 15, 2026, CISA added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to the KEV catalog based on evidence of active exploitation.
On May 8, 2026, CISA added CVE-2026-42208, a SQL injection vulnerability affecting BerriAI LiteLLM, to the KEV catalog after determining there was evidence of active exploitation.
On May 7, 2026, CISA added CVE-2026-6973, an improper input validation vulnerability affecting Ivanti Endpoint Manager Mobile, to the KEV catalog based on active exploitation.
On May 1, 2026, CISA added CVE-2026-31431, a Linux Kernel incorrect resource transfer between spheres vulnerability, to the KEV catalog after obtaining evidence of active exploitation.
On April 24, 2026, CISA added four vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and the D-Link DIR-823X to the KEV catalog. The flaws included path traversal, missing authorization, and command injection issues under active exploitation.
On April 23, 2026, CISA added CVE-2026-39987, a Marimo remote code execution vulnerability, to the KEV catalog based on evidence of active exploitation.
On April 22, 2026, CISA added CVE-2026-33825, a Microsoft Defender insufficient granularity of access control vulnerability, to the KEV catalog after determining there was evidence of active exploitation.
On April 20, 2026, CISA added eight vulnerabilities affecting PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra Collaboration Suite, and Cisco Catalyst SD-WAN Manager to the KEV catalog. CISA said the additions were based on evidence of active exploitation.
On April 16, 2026, CISA added CVE-2026-34197, an Apache ActiveMQ improper input validation vulnerability, to the KEV catalog after determining there was evidence of active exploitation.
On April 14, 2026, CISA added CVE-2009-0238, a Microsoft Office remote code execution flaw, and CVE-2026-32201, a Microsoft SharePoint Server improper input validation vulnerability, to the KEV catalog.
On April 13, 2026, CISA added seven new vulnerabilities to the KEV catalog affecting Microsoft Visual Basic for Applications, Adobe Acrobat, Microsoft Exchange Server, Microsoft Windows, Fortinet products, and Adobe Acrobat and Reader. The agency said all seven had evidence of active exploitation.
On April 8, 2026, CISA added CVE-2026-1340, a code injection vulnerability affecting Ivanti Endpoint Manager Mobile, to the KEV catalog after determining there was evidence of active exploitation.
On April 6, 2026, CISA added CVE-2026-35616, an improper access control vulnerability affecting Fortinet FortiClient EMS, to the KEV catalog based on active exploitation.
On April 1, 2026, CISA added CVE-2026-5281, a Google Dawn use-after-free vulnerability, to the KEV catalog after determining there was evidence of active exploitation.
On March 27, 2026, CISA added CVE-2025-53521, an F5 BIG-IP remote code execution vulnerability, to the KEV catalog after obtaining evidence of active exploitation.
On March 26, 2026, CISA added CVE-2026-33634, identified as an Aqua Security Trivy Embedded Malicious Code vulnerability, to the KEV catalog based on active exploitation evidence.
On March 25, 2026, CISA added CVE-2026-33017, a Langflow code injection vulnerability, to the KEV catalog after obtaining evidence of active exploitation.
On March 19, 2026, CISA added CVE-2026-20131 affecting Cisco Secure Firewall Management Center and Cisco Security Cloud Control Firewall Management to the KEV catalog. The flaw was described as a deserialization of untrusted data issue under active exploitation.
On March 18, 2026, CISA added CVE-2025-66376, a cross-site scripting vulnerability affecting Synacor Zimbra Collaboration Suite, to the KEV catalog based on active exploitation.
On March 16, 2026, CISA added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to the KEV catalog after evidence of active exploitation emerged.
On March 13, 2026, CISA added CVE-2026-3909, a Google Skia out-of-bounds write flaw, and CVE-2026-3910, a Google Chromium V8 vulnerability, to the KEV catalog. The agency said both were being actively exploited.
On March 11, 2026, CISA added CVE-2025-68613 affecting n8n to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. CISA described it as an improper control of dynamically managed code resources issue.
On March 9, 2026, CISA added CVE-2026-1603 in Ivanti Endpoint Manager, CVE-2025-26399 in SolarWinds Web Help Desk, and CVE-2021-22054 in Omnissa Workspace ONE to the KEV catalog based on active exploitation. The listed issues included authentication bypass, deserialization-based remote code execution, and server-side request forgery.
On March 5, 2026, CISA added three actively exploited Apple vulnerabilities affecting macOS, iOS, iPadOS, Safari, and related platforms to its Known Exploited Vulnerabilities catalog. The flaws included two use-after-free issues and one integer overflow issue that could lead to memory corruption, arbitrary code execution, or kernel-privileged code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
41 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcegithub.com
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcethecyberthrone.in
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.