CISA Adds Two Known Exploited ... Note

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities, CVE-2026-48939 affecting iCagenda and CVE-2026-56291 affecting Balbooa Forms, to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities involve the unrestricted upload of dangerous file types, a common attack method for cybercriminals. Such vulnerabilities present substantial risks to federal systems. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive emphasizes rapid patching of high-risk vulnerabilities on publicly exposed assets that allow complete control after exploitation. Agencies are also expected to verify if systems were compromised before patching. While BOD 26-04 specifically targets federal agencies, CISA advises all organizations to implement risk-based vulnerability management and address KEV Catalog entries. CISA will continue to add vulnerabilities that meet the established criteria. Organizations can submit vulnerabilities for consideration if they have a CVE ID, proof of exploitation, and clear mitigation steps, using CISA's KEV Nomination Form.