CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA updated its Known Exploited Vulnerabilities (KEV) Catalog, adding a new vulnerability. The new vulnerability is CVE-2026-48172, a privilege escalation flaw in the LiteSpeed cPanel Plugin. This type of vulnerability is often exploited by attackers, posing significant risks. The KEV Catalog is a list of known vulnerabilities with substantial risks, as established by Binding Operational Directive 22-01. BOD 22-01 mandates that Federal Civilian Executive Branch agencies fix identified vulnerabilities promptly. This directive aims to protect federal networks from existing threats. The provided fact sheet offers further details about BOD 22-01. While BOD 22-01 mainly applies to federal agencies, other organizations are strongly encouraged to use the KEV Catalog. Prioritizing remediation of KEV vulnerabilities helps reduce exposure to cyberattacks. CISA plans to continuously add vulnerabilities to the catalog as needed.