CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-45659, a Microsoft SharePoint Server deserialization vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. This vulnerability represents a significant threat to federal networks, as deserialization flaws are common attack methods. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies manage vulnerabilities based on risk. This directive emphasizes the KEV Catalog and requires agencies to quickly fix high-risk vulnerabilities listed there on exposed assets. Such vulnerabilities, when exploited, can grant attackers complete control over affected systems. BOD 26-04 also sets expectations for agencies to check for compromises before patching. Although BOD 26-04 applies only to FCEB agencies, CISA strongly recommends that all organizations adopt a risk-based approach to vulnerability management. CISA will consistently update the KEV Catalog with vulnerabilities that meet their criteria. Organizations can nominate vulnerabilities for the KEV Catalog if they have a CVE ID, proof of exploitation, and clear remediation steps.