CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-35273, an Oracle PeopleSoft vulnerability, to its Known Exploited Vulnerabilities catalog. This vulnerability involves missing authentication for critical functions and is a common attack method for malicious actors. It presents considerable risks to federal systems. Binding Operational Directive (BOD) 26-04, which updates BOD 22-01, sets vulnerability management requirements for federal agencies. This directive emphasizes the KEV catalog and mandates rapid patching of high-risk vulnerabilities on publicly exposed assets that lead to complete control post-exploitation. Lower-risk vulnerabilities can be addressed later according to BOD 26-04. The directive also outlines expectations for agencies to check for compromise before applying patches. Although BOD 26-04 is specific to federal agencies, CISA recommends all organizations implement risk-based vulnerability management. Prioritizing KEV catalog vulnerabilities is encouraged for everyone. CISA will continue to augment the KEV catalog with qualifying vulnerabilities. Organizations can submit vulnerabilities for consideration if they have a CVE ID, evidence of exploitation, and clear mitigation guidance.