Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-facing-service-vulnerabilitywidely-deployed-product-advisory

CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog

Updated 3mo agoFirst seen Jan 27, 20266 sources

CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, reinforcing that these issues are being used as real-world attack vectors and should be prioritized for remediation. The newly listed CVEs are CVE-2018-14634 (Linux kernel integer overflow / local privilege escalation), CVE-2025-52691 (SmarterTools SmarterMail unrestricted file upload enabling RCE), CVE-2026-21509 (Microsoft Office security feature bypass), CVE-2026-23760 (SmarterTools SmarterMail authentication bypass via alternate path/channel), and CVE-2026-24061 (GNU InetUtils argument injection). CISA reiterated that these vulnerability classes are frequently leveraged by threat actors and pose material risk to enterprise environments.

Under BOD 22-01, U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed vulnerabilities by CISA-specified due dates, and CISA urged all organizations to treat KEV entries as high-priority items in vulnerability management. Additional technical context highlighted that CVE-2025-52691 can enable unauthenticated arbitrary file upload leading to remote code execution (noted as CVSS 10.0 in the reporting) and that CVE-2018-14634, while older, remains relevant where legacy Linux kernels persist—underscoring that KEV additions can include long-standing flaws when exploitation is observed in the wild.

Share:
CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 27, 20265mo ago

CISA adds Fortinet CVE-2026-24858 to the KEV catalog

CISA added CVE-2026-24858, an authentication bypass using an alternate path or channel affecting multiple Fortinet products, to the Known Exploited Vulnerabilities catalog. The listing indicated evidence of active exploitation and elevated risk to federal networks.

Jan 26, 20265mo ago

CISA sets February 16 remediation deadline for the five new KEV entries

Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the five newly listed KEV vulnerabilities by February 16, 2026. CISA also urged all organizations to prioritize patching because of evidence of active exploitation.

CISA adds five exploited vulnerabilities to the KEV catalog

CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2018-14634, CVE-2025-52691, CVE-2026-23760, CVE-2026-21509, and CVE-2026-24061. The issues affected the Linux kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils.

Jan 1, 20266mo ago

Microsoft issues out-of-band updates for exploited Office zero-day

Microsoft released out-of-band updates for CVE-2026-21509, a Microsoft Office security feature bypass being actively exploited. The company said exploitation required a user to open a malicious Office file and that the Preview Pane was not an attack vector.

Jan 1, 20251y ago

SmarterMail file-upload flaw is publicly warned on by Singapore CSA

Singapore's Cyber Security Agency warned about SmarterTools SmarterMail CVE-2025-52691, describing it as a maximum-severity issue that could enable unauthenticated arbitrary file upload and remote code execution. It recommended upgrading from Build 9406 and earlier to Build 9413.

Oct 17, 20188y ago

Linux kernel privilege-escalation flaw CVE-2018-14634 is disclosed

Qualys disclosed CVE-2018-14634, a Linux kernel integer overflow/local privilege-escalation vulnerability later nicknamed "Mutagen Astronomy." The flaw affected multiple kernel branches and allowed an unprivileged local user to gain root privileges.

Mar 19, 201511y ago

GNU InetUtils telnetd flaw is introduced in source code

A commit on March 19, 2015 introduced the code path that later became CVE-2026-24061 in GNU InetUtils telnetd. The bug enabled argument injection that could lead to authentication bypass and root compromise in affected versions.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog | Mallory