CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has included two new vulnerabilities in its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, CVE-2024-1708 (ConnectWise ScreenConnect) and CVE-2026-32202 (Microsoft Windows), are actively being exploited. These types of flaws often lead to cyberattacks and pose substantial risks, especially to government networks. BOD 22-01 established the KEV Catalog to identify and mandate the patching of critical vulnerabilities. This directive requires Federal Civilian Executive Branch agencies to fix these vulnerabilities promptly. The due dates for remediation are set to protect networks from current threats. While BOD 22-01 focuses on federal agencies, CISA advises all organizations to prioritize KEV Catalog remediation. This proactive action helps reduce their vulnerability to cyberattacks. Organizations should integrate KEV remediation into their established vulnerability management processes. CISA will continue monitoring and adding vulnerabilities to the catalog as new threats emerge.