CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog by adding one new vulnerability, CVE-2026-9082, a Drupal Core SQL Injection vulnerability. This vulnerability is included due to evidence of active exploitation by malicious actors. SQL injection vulnerabilities are commonly exploited, posing a considerable risk to systems. The KEV Catalog is maintained under Binding Operational Directive (BOD) 22-01. This directive requires Federal Civilian Executive Branch (FCEB) agencies to patch these vulnerabilities by specified deadlines. The goal is to protect federal networks from existing threats and vulnerabilities. The BOD 22-01 fact sheet provides further details on the directive and its implementation. While BOD 22-01 focuses on FCEB agencies, CISA recommends that all organizations address these vulnerabilities promptly. Organizations outside the FCEB should also prioritize the remediation of KEV vulnerabilities to stay secure. CISA will regularly update the catalog as new vulnerabilities meeting the criteria emerge. This proactive approach helps to improve overall cybersecurity posture and minimize potential damage.