CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has identified two new vulnerabilities that are actively being exploited and added them to its Known Exploited Vulnerabilities (KEV) Catalog. These newly added vulnerabilities are CVE-2026-42271 affecting BerriAI LiteLLM and CVE-2026-50751 impacting Check Point Security Gateway. Such vulnerabilities represent common attack methods for cybercriminals and pose substantial threats to federal networks. The KEV Catalog, established by Binding Operational Directive 22-01, lists known vulnerabilities with significant risk to the federal enterprise. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies must fix these identified vulnerabilities by a specific deadline. The goal is to safeguard FCEB networks from current cyber threats. Although BOD 22-01 specifically targets FCEB agencies, CISA strongly advises all organizations to address these KEV Catalog vulnerabilities. Prioritizing their remediation is crucial for enhancing an organization's cybersecurity posture. CISA will continue to update the KEV Catalog with new vulnerabilities that meet the established criteria. This ongoing effort aims to provide timely information on critical security issues.