CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These include an IBM Langflow code injection vulnerability, an N-able N-central authentication bypass, and an Apache Tomcat missing encryption vulnerability. Actively exploited vulnerabilities are common attack vectors for cyber actors, posing serious risks to federal systems. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the rapid remediation of high-risk vulnerabilities identified in the KEV Catalog. This directive specifically focuses on vulnerabilities that grant total control of publicly exposed assets after exploitation. BOD 26-04 also outlines requirements for agencies to check for compromises before applying patches. While the directive applies only to FCEB agencies, CISA recommends all organizations adopt a risk-based approach. CISA will continue to add qualifying vulnerabilities to the KEV Catalog. Organizations aware of exploited vulnerabilities not yet in the catalog can submit them for consideration. Submissions require a CVE ID, evidence of exploitation, and clear mitigation guidance.