CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These include CVE-2023-49105 in ownCloud, CVE-2026-53362 in the Linux Kernel, and CVE-2026-66384 in JFrog Artifactory. These vulnerabilities are frequently exploited by malicious actors and pose substantial risks. Federal Civilian Executive Branch agencies must comply with Binding Operational Directive (BOD) 26-04, which mandates prioritizing the remediation of high-risk vulnerabilities. Specifically, BOD 26-04 requires agencies to focus on vulnerabilities listed in the KEV Catalog on publicly exposed assets that grant full control after exploitation. The directive also outlines expectations for agencies to check for system compromises before applying patches. While BOD 26-04 applies only to federal agencies, CISA recommends all organizations adopt a risk-based approach to vulnerability management. This includes prioritizing the remediation of vulnerabilities found in the KEV Catalog. CISA will continue to add vulnerabilities to the KEV Catalog as they meet the criteria. Organizations can submit potential KEV additions via CISA's KEV Nomination Form if they are aware of exploited vulnerabilities not yet listed. Submissions require a CVE ID, evidence of exploitation, and clear mitigation guidance.