CISA issued Emergency Directive 25-03 ordering federal civilian agencies to identify and mitigate potential compromise of Cisco devices, then followed with supplemental guidance covering core-dump collection and threat-hunting steps. The directive indicates concern that Cisco infrastructure may already have been breached and requires agencies to validate device integrity, investigate for signs of compromise, and take remediation actions to reduce ongoing risk.
At the same time, CISA continued expanding its Known Exploited Vulnerabilities catalog with numerous newly listed flaws, including CVE-2026-33634, CVE-2026-5281, CVE-2026-32201, CVE-2026-3502, CVE-2026-33017, CVE-2026-20131, CVE-2026-3909, CVE-2026-1603, CVE-2026-21385, CVE-2026-22719, CVE-2026-2441, and CVE-2026-1281, alongside older but still exploited issues such as CVE-2025-40551, CVE-2025-20393, CVE-2025-15556, CVE-2024-43468, CVE-2023-48788, CVE-2021-44529, and CVE-2021-39935. The combined actions show U.S. authorities escalating warnings that active exploitation is broadening across enterprise technologies, with network appliances, email platforms, and internet-facing systems remaining priority targets for defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
31 events from the most recent confirmed update back to the earliest known activity.
CISA published guidance addressing CVE-2023-4966, known as Citrix Bleed, affecting Citrix NetScaler ADC and Gateway devices. The guidance provided mitigation direction for organizations responding to the actively exploited vulnerability.
CISA published a Known Exploited Vulnerabilities catalog entry or search-indexed listing for CVE-2026-20963, indicating the vulnerability was known to be exploited in the wild. The addition elevated the urgency of remediation for affected organizations, especially federal agencies.
CISA published a Known Exploited Vulnerabilities catalog entry or search-indexed listing for CVE-2025-68613, indicating the vulnerability was known to be exploited. The publication elevated remediation priority for affected organizations, particularly federal agencies.
CISA published or refreshed multiple KEV search-result pages for previously listed CVEs, including CVE-2026-32201, CVE-2025-60710, CVE-2026-3502, CVE-2026-33017, CVE-2026-20131, CVE-2025-32432, CVE-2025-31277, CVE-2025-43510, CVE-2025-43520, CVE-2023-48788, CVE-2021-44529, CVE-2026-3909, CVE-2026-1603, CVE-2026-21385, CVE-2026-22719, CVE-2026-2441, CVE-2025-15556, CVE-2024-43468, CVE-2026-1281, CVE-2021-39935, and CVE-2025-20393. Based on the provided data, these are catalog/search refreshes and do not provide enough detail to separate them into distinct real-world incident events.
CISA republished or refreshed catalog search results for CVE-2025-26399 on its KEV site. This appears to be a site indexing or search update rather than a distinct new exploitation event.
CISA published Version 1 of ED 25-03, continuing guidance to identify and mitigate potential compromise of Cisco devices. The updated directive indicated an ongoing federal response and refined mitigation expectations.
CISA added CVE-2026-5281 to the Known Exploited Vulnerabilities catalog. The listing reflected active exploitation and increased urgency for remediation.
CISA published a KEV entry for CVE-2026-33634, indicating the vulnerability was known to be exploited. The addition required prompt mitigation by affected entities.
CISA added CVE-2025-26399 to its KEV catalog, identifying it as actively exploited. The publication elevated the vulnerability's remediation priority.
HHS' Office for Civil Rights announced a settlement of its HIPAA investigation into MMG Fusion, LLC following a breach affecting 15 million individuals. The action represented a regulatory resolution tied to a large healthcare data breach.
CISA published a Known Exploited Vulnerabilities entry for CVE-2026-20127. The listing reflected confirmed exploitation and prompted prioritization of defensive action.
CISA added CVE-2026-1731 to the KEV catalog, indicating the vulnerability had been exploited. The entry made the flaw subject to heightened remediation urgency.
CISA published a KEV entry for CVE-2025-11953, identifying it as a known exploited flaw. The addition signaled that affected organizations should prioritize mitigation.
CISA added CVE-2026-24423 to the Known Exploited Vulnerabilities catalog. The listing indicated exploitation in the wild and required accelerated remediation attention.
CISA published a KEV listing for CVE-2025-40551, marking it as actively exploited. The catalog addition elevated patching priority for affected systems.
CISA added CVE-2025-64328 to its Known Exploited Vulnerabilities catalog. The entry signaled observed exploitation and the need for prompt mitigation.
CISA published a KEV entry for CVE-2026-23760, indicating the flaw was known to be exploited. The addition placed the vulnerability into federal remediation workflows.
CISA published the closed version of Emergency Directive 21-01 concerning mitigation of the SolarWinds Orion code compromise. This reflected archival or status-updated publication of the directive on CISA's site.
CISA added CVE-2025-37164 to the KEV catalog, identifying it as a known exploited vulnerability. The listing increased urgency for patching and mitigation among affected organizations.
The FBI published an alert stating that the Silent Ransom Group was targeting law firms. The warning represented a law enforcement notification to a specific sector about an active threat campaign.
CISA published a Known Exploited Vulnerabilities catalog entry for CVE-2025-59718, indicating the vulnerability was known to be exploited in the wild. The addition elevated the urgency of remediation for affected organizations, especially federal agencies.
CISA published a Known Exploited Vulnerabilities entry for CVE-2025-54236. The addition indicated active exploitation and triggered prioritization for mitigation.
CISA released a supplemental direction to ED 25-03 providing core dump collection and threat hunting instructions. The update expanded the government's response guidance for investigating suspected Cisco device compromise.
CISA published Emergency Directive 25-03 instructing agencies to identify and mitigate potential compromise affecting Cisco devices. The directive reflected concern that impacted devices may already have been compromised and required immediate defensive action.
CISA added CVE-2025-4428 to the KEV catalog, signaling that exploitation had been observed in the wild. The listing made the vulnerability a priority for federal remediation timelines.
CISA added CVE-2024-23113 to the Known Exploited Vulnerabilities catalog. The entry indicated the flaw was being exploited and should be remediated on an accelerated basis.
CISA published a KEV entry for CVE-2024-28986, identifying it as a vulnerability under active exploitation. The addition required heightened patching priority for impacted systems.
HHS' Office for Civil Rights announced it had issued a letter and opened an investigation into the Change Healthcare cyberattack. The action signaled federal scrutiny of potential HIPAA-related impacts from the incident.
CISA added CVE-2024-21762 to its Known Exploited Vulnerabilities catalog, reflecting confirmed exploitation activity. The listing elevated urgency for remediation across affected organizations, especially federal agencies.
CISA published a Known Exploited Vulnerabilities catalog entry for CVE-2020-0796, indicating the vulnerability was known to be exploited in the wild. Federal agencies would be expected to prioritize remediation under KEV requirements.
CISA issued Binding Operational Directive 17-01 directing federal agencies to identify and remove Kaspersky-branded products from federal information systems. This marked a formal U.S. government mitigation action against the vendor's software in federal environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcefbi.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.