CISA Adds Two Known Exploited ... Note

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities, CVE-2026-72529 and CVE-2026-72530, affecting TrueConf Server to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities have been confirmed to be actively exploited by malicious actors. Such vulnerabilities represent a significant threat to the federal enterprise due to their common use in cyberattacks. Binding Operational Directive 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially those on publicly accessible assets. This directive emphasizes a risk-based approach, focusing on high-risk vulnerabilities that grant complete control after exploitation. Agencies are also required to check for system compromise before applying patches for listed vulnerabilities. Although BOD 26-04 is specific to FCEB agencies, CISA strongly recommends that all organizations implement similar risk-based vulnerability management practices. CISA plans to continue adding vulnerabilities to the KEV Catalog as evidence of exploitation emerges. Organizations can nominate vulnerabilities for potential inclusion to the KEV Catalog if they have a CVE ID, proof of exploitation, and accessible mitigation steps.