CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These include CVE-2026-16232, a Check Point SmartConsole improper authentication vulnerability, and CVE-2026-50522, a Microsoft SharePoint deserialization of untrusted data vulnerability. Such vulnerabilities are common attack vectors for cyber actors and pose significant risks. Binding Operational Directive (BOD) 26-04 mandates vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. This directive emphasizes the KEV Catalog and requires agencies to prioritize rapid remediation of high-risk vulnerabilities listed within it on publicly exposed assets. BOD 26-04 also sets expectations for agencies to check for compromises before patches are applied. While BOD 26-04 applies specifically to FCEB agencies, CISA urges all organizations to implement risk-based vulnerability management. They encourage prioritizing the remediation of vulnerabilities already documented in the KEV Catalog. CISA will persist in adding newly identified exploited vulnerabilities to the catalog. Organizations can submit exploited vulnerabilities not yet listed to CISA via their KEV Nomination Form, provided they have a CVE ID, exploitation evidence, and clear mitigation guidance.