CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, a list of actively exploited vulnerabilities. Two new vulnerabilities, CVE-2025-34291 and CVE-2026-34926, were added due to confirmed active exploitation. These vulnerabilities, like others in the catalog, are often used as attack vectors. These pose great risks to federal networks and other organizations. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01. BOD 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies remediate listed vulnerabilities. Agencies must follow the specified due dates in order to protect against threats. While BOD 22-01 directs FCEB agencies, CISA advises all organizations to prioritize KEV remediation. Timely remediation is a strong part of any proper vulnerability management strategy. CISA will continually update the catalog with new vulnerabilities to enhance protection.