CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These are CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager and CVE-2026-54420 impacting LiteSpeed cPanel Plugin. Such vulnerabilities are common attack methods for cybercriminals. Federal agencies are mandated to address these risks through Binding Operational Directive (BOD) 26-04. This directive requires FCEB agencies to prioritize patching vulnerabilities listed in the KEV catalog that are on public-facing assets and offer complete system control. BOD 26-04 updates previous directives and reinforces the significance of the KEV catalog. It also outlines expectations for agencies to check for potential compromises before applying patches. While this directive specifically targets FCEB agencies, CISA urges all organizations to adopt similar risk-based vulnerability management. CISA will continue to update the KEV catalog with newly identified exploited vulnerabilities. Organizations can nominate vulnerabilities for inclusion in the KEV catalog if they have a CVE ID, proof of exploitation, and clear mitigation steps.