CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-31431, to its Known Exploited Vulnerabilities (KEV) Catalog. This Linux Kernel vulnerability is actively being exploited by malicious actors. Such vulnerabilities present a significant risk to federal government systems. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies fix KEV vulnerabilities by a set deadline. The goal is to protect FCEB networks from active cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly advises all organizations to address these vulnerabilities. Prioritizing remediation of KEV Catalog entries is crucial for reducing cyberattack exposure. This proactive approach should be integrated into regular vulnerability management. CISA will continue to update the KEV Catalog with newly identified vulnerabilities that meet the established criteria.