CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has identified and added CVE-2026-39987, a Marimo Remote Code Execution Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is currently being actively exploited by malicious actors. Remote code execution vulnerabilities are common attack methods that present substantial risks to federal systems. CISA established the KEV Catalog through Binding Operational Directive (BOD) 22-01 to identify high-risk vulnerabilities. BOD 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies must fix these vulnerabilities by a specific deadline. This directive aims to protect FCEB networks from ongoing cyber threats. While BOD 22-01 applies only to FCEB agencies, CISA strongly recommends all organizations address these vulnerabilities. Prioritizing the remediation of cataloged vulnerabilities is crucial for effective vulnerability management. CISA will continue to update the KEV Catalog with new vulnerabilities that meet its criteria. This ongoing effort helps organizations mitigate significant cyber risks.