CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-45247, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Mirasvit Full Page Cache Warmer and is due to deserialization of untrusted data. Such vulnerabilities are common attack vectors for cyber actors and present significant risks. CISA's Binding Operational Directive 22-01 created the KEV Catalog to highlight vulnerabilities posing a serious threat to the federal enterprise. This directive mandates that Federal Civilian Executive Branch agencies fix these vulnerabilities by specific deadlines. The goal is to protect FCEB networks from active threats. While BOD 22-01 specifically targets FCEB agencies, CISA encourages all organizations to address KEV Catalog vulnerabilities. Prioritizing remediation is crucial for reducing exposure to cyberattacks. CISA will continue to update the KEV Catalog with vulnerabilities that meet its criteria. This ongoing effort aims to enhance overall cybersecurity posture.