CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-48282, an Adobe ColdFusion Path Traversal Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This type of vulnerability is a common attack method for cybercriminals, posing serious threats to federal systems. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch agencies manage vulnerabilities by prioritizing those on the KEV Catalog. This directive specifically requires rapid remediation of high-risk KEV vulnerabilities on publicly accessible assets that allow full control after exploitation. Agencies are also expected to regularly check for compromises preceding patch application. Although BOD 26-04 applies only to federal agencies, CISA recommends all organizations implement risk-based vulnerability management. They encourage prioritizing remediation of KEV Catalog vulnerabilities regardless of sector. CISA will continue to add vulnerabilities meeting their criteria to the KEV Catalog. Organizations aware of exploited vulnerabilities not yet in the catalog can submit them for consideration. Submissions require a CVE ID, proof of exploitation, and clear mitigation steps.