CISA | Alerts
Follow
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. These include two SonicWall SMA1000 Appliances vulnerabilities (CVE-2026-15409 and CVE-2026-15410) and two Microsoft vulnerabilities for Active Directory Federation Services (CVE-2026-56155) and SharePoint Server (CVE-2026-56164). These types of vulnerabilities are common attack vectors posing significant risks. Binding Operational Directive 26-04 mandates that federal civilian executive branch agencies prioritize the remediation of vulnerabilities on the KEV Catalog, especially those on publicly exposed assets that grant total control post-exploitation. The directive also sets expectations for checking for prior compromise before applying patches. While BOD 26-04 is specific to FCEB agencies, CISA urges all organizations to adopt risk-based vulnerability management and address KEV Catalog items. CISA plans to continue adding vulnerabilities that meet their criteria to the KEV Catalog. Organizations can nominate newly discovered, actively exploited vulnerabilities with a CVE ID and mitigation guidance for inclusion.