CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a critical Gitea code injection vulnerability, CVE-2026-60004, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. This type of vulnerability is a common attack method for malicious actors and presents major risks. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize security updates for vulnerabilities listed in the KEV Catalog. This directive emphasizes rapid remediation of high-risk vulnerabilities on publicly exposed assets that grant complete control post-exploitation. BOD 26-04 also sets expectations for agencies to check for system compromises before applying patches. While the directive specifically targets FCEB agencies, CISA urges all organizations to implement risk-based vulnerability management. Organizations are encouraged to prioritize fixing vulnerabilities found in the KEV Catalog. CISA will continue to add vulnerabilities that meet the criteria for active exploitation. If an exploited vulnerability is known but not yet in the KEV Catalog, it can be nominated for addition. Nominations require a CVE ID, evidence of exploitation, and clear mitigation information.