CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding a new vulnerability. The newly added vulnerability is CVE-2026-1340, a code injection flaw in Ivanti Endpoint Manager Mobile (EPMM). This vulnerability is actively being exploited by malicious actors, posing a considerable threat. The KEV Catalog is a list of vulnerabilities posing significant risks, as defined by Binding Operational Directive (BOD) 22-01. BOD 22-01 mandates federal agencies remediate vulnerabilities in the catalog by set deadlines. This directive aims to safeguard federal networks from active cyber threats. Remediation efforts are crucial to minimize potential exploits of these known vulnerabilities. While BOD 22-01 applies only to federal agencies, other organizations are strongly encouraged to adopt the practices. Timely remediation of KEV catalog vulnerabilities is vital for overall cyber security. CISA will continue to augment the KEV catalog with any newly discovered critical vulnerabilities.