CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-20253, a Splunk Enterprise vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. This critical vulnerability allows unauthorized access and poses significant risks to government systems. Binding Operational Directive (BOD) 26-04 now mandates that Federal Civilian Executive Branch agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive, updating BOD 22-01, emphasizes rapid action on high-risk vulnerabilities that provide complete control after exploitation. Lower-risk vulnerabilities can be deferred, but agencies must now proactively check for compromises before patching. While BOD 26-04 specifically targets federal agencies, CISA strongly recommends all organizations adopt similar risk-based vulnerability management practices. The agency will continue to add vulnerabilities to the KEV Catalog as they are identified and exploited. Organizations can nominate vulnerabilities for inclusion in the KEV Catalog if they have a CVE ID, proof of exploitation, and clear mitigation steps. This proactive approach aims to strengthen cybersecurity defenses against prevalent threats.