CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a new vulnerability, CVE-2026-41940, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects WebPros cPanel & WHM and WP2, specifically a missing authentication for a critical function. Such vulnerabilities are commonly exploited by malicious actors and present significant risks. The KEV Catalog was established by Binding Operational Directive 22-01 to list vulnerabilities posing significant risk to the federal enterprise. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities by a set deadline. The goal is to protect FCEB networks from active threats. While BOD 22-01 is specific to FCEB agencies, CISA strongly recommends all organizations follow suit. Prioritizing the remediation of KEV Catalog vulnerabilities is crucial for reducing cyberattack exposure. This practice should be integrated into overall vulnerability management. CISA intends to continue adding vulnerabilities that meet their criteria to the catalog.