CISA Adds Two Known Exploited ... Note

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, a list of actively exploited vulnerabilities. Two new vulnerabilities have been added to the catalog due to confirmed exploitation. The first vulnerability, CVE-2009-0238, impacts Microsoft Office and involves remote code execution. The second vulnerability, CVE-2026-32201, affects Microsoft SharePoint Server and concerns improper input validation. These vulnerabilities are attractive targets for malicious actors and pose substantial risks primarily to federal networks. The KEV Catalog was created by Binding Operational Directive (BOD) 22-01 to address these risks. BOD 22-01 mandates that Federal Civilian Executive Branch agencies remediate these vulnerabilities promptly. Agencies must meet specified deadlines to safeguard their networks against active threats. CISA encourages all organizations, even those not under BOD 22-01, to prioritize KEV remediation. Timely remediation helps mitigate cyberattack risks within any organization’s vulnerability management program. CISA will regularly update the KEV Catalog with additional vulnerabilities meeting the necessary criteria.