CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-85706, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This adds a path traversal vulnerability affecting GitLab Community Edition and Enterprise Edition to the catalog. Path traversal vulnerabilities are common attack methods for cybercriminals. The addition highlights the risks these vulnerabilities pose to federal systems. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize patching vulnerabilities listed in the KEV Catalog. This directive emphasizes rapid remediation of high-risk vulnerabilities on public-facing assets that grant full control post-exploitation. BOD 26-04 also sets expectations for agencies to check for compromise before applying patches. Although BOD 26-04 is specific to FCEB agencies, CISA recommends all organizations adopt this risk-based approach to vulnerability management. CISA will continue to update the KEV Catalog with qualifying vulnerabilities. Organizations can nominate vulnerabilities they believe should be added to the KEV Catalog if they have a CVE ID, proof of exploitation, and mitigation details.