CISA Adds Five Actively Exploited Vulnerabilities to the KEV Catalog
CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, reinforcing that these issues are being used as real-world attack vectors and should be prioritized for remediation. The newly listed CVEs are CVE-2018-14634 (Linux kernel integer overflow / local privilege escalation), CVE-2025-52691 (SmarterTools SmarterMail unrestricted file upload enabling RCE), CVE-2026-21509 (Microsoft Office security feature bypass), CVE-2026-23760 (SmarterTools SmarterMail authentication bypass via alternate path/channel), and CVE-2026-24061 (GNU InetUtils argument injection). CISA reiterated that these vulnerability classes are frequently leveraged by threat actors and pose material risk to enterprise environments.
Under BOD 22-01, U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed vulnerabilities by CISA-specified due dates, and CISA urged all organizations to treat KEV entries as high-priority items in vulnerability management. Additional technical context highlighted that CVE-2025-52691 can enable unauthenticated arbitrary file upload leading to remote code execution (noted as CVSS 10.0 in the reporting) and that CVE-2018-14634, while older, remains relevant where legacy Linux kernels persist—underscoring that KEV additions can include long-standing flaws when exploitation is observed in the wild.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
CISA adds Fortinet CVE-2026-24858 to the KEV catalog
CISA added CVE-2026-24858, an authentication bypass using an alternate path or channel affecting multiple Fortinet products, to the Known Exploited Vulnerabilities catalog. The listing indicated evidence of active exploitation and elevated risk to federal networks.
CISA sets February 16 remediation deadline for the five new KEV entries
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the five newly listed KEV vulnerabilities by February 16, 2026. CISA also urged all organizations to prioritize patching because of evidence of active exploitation.
CISA adds five exploited vulnerabilities to the KEV catalog
CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2018-14634, CVE-2025-52691, CVE-2026-23760, CVE-2026-21509, and CVE-2026-24061. The issues affected the Linux kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils.
Microsoft issues out-of-band updates for exploited Office zero-day
Microsoft released out-of-band updates for CVE-2026-21509, a Microsoft Office security feature bypass being actively exploited. The company said exploitation required a user to open a malicious Office file and that the Preview Pane was not an attack vector.
SmarterMail file-upload flaw is publicly warned on by Singapore CSA
Singapore's Cyber Security Agency warned about SmarterTools SmarterMail CVE-2025-52691, describing it as a maximum-severity issue that could enable unauthenticated arbitrary file upload and remote code execution. It recommended upgrading from Build 9406 and earlier to Build 9413.
Linux kernel privilege-escalation flaw CVE-2018-14634 is disclosed
Qualys disclosed CVE-2018-14634, a Linux kernel integer overflow/local privilege-escalation vulnerability later nicknamed "Mutagen Astronomy." The flaw affected multiple kernel branches and allowed an unprivileged local user to gain root privileges.
GNU InetUtils telnetd flaw is introduced in source code
A commit on March 19, 2015 introduced the code path that later became CVE-2026-24061 in GNU InetUtils telnetd. The bug enabled argument injection that could lead to authentication bypass and root compromise in affected versions.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
6 references tracked. Mallory keeps watching after this page renders.
CISA adds critical Microsoft Office, Linux Kernel, and SmarterMail vulnerabilities to KEV catalog | SC Media
scworld.com
Open sourceU.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com
Open sourceCISA Adds One Known Exploited Vulnerability to Catalog | CISA
cisa.gov
Open sourceCISA KEV Catalog Update - 5 Vulnerabilities Added - TheCyberThrone
thecyberthrone.in
Open sourceCISA KEV Jan 2026: Five Exploited CVEs Signal Urgent Patch Playbook | Windows Forum
windowsforum.com
Open sourceCISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA
cisa.gov
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.

