Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-vulnerability-catalogactively-exploited-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerability

CISA Adds Four Actively Exploited Vulnerabilities to the KEV Catalog

Updated 3mo agoFirst seen Feb 17, 20266 sources

CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2008-0015 (Microsoft Windows Video ActiveX Control RCE), CVE-2020-7796 (Synacor Zimbra Collaboration Suite SSRF, noted as relevant when the WebEx zimlet is installed and zimlet JSP is enabled), CVE-2024-7694 (TeamT5 ThreatSonar Anti-Ransomware unrestricted file upload that can enable server-side command execution when an attacker has admin access to the platform), and CVE-2026-2441 (Google Chromium CSS use-after-free). Under BOD 22-01, U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed issues by CISA’s specified due dates, and CISA urged all organizations to prioritize remediation as part of vulnerability management.

CISA’s public KEV data repository was updated to reflect the new catalog release (increasing the total count and adding entries including CVE-2020-7796 and CVE-2024-7694 with remediation guidance and metadata). Separately, industry commentary emphasized that KEV is best used as a prioritization input rather than a blanket “panic list,” recommending teams weigh exploitability context (e.g., required privileges/local access vs. remote control) and combine KEV with other signals such as CVSS, EPSS, and observed exploit tooling to drive patch sequencing.

Share:
CISA Adds Four Actively Exploited Vulnerabilities to the KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 18, 20264mo ago

TeamT5 says customers migrated off vulnerable ThreatSonar versions

TeamT5 later stated that affected customers had already migrated away from vulnerable ThreatSonar Anti-Ransomware versions. The company also said it had improved its secure development lifecycle and security processes in response.

Feb 17, 20264mo ago

CISA sets March 10 remediation deadline for newly added KEV flaws

Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the four newly added KEV vulnerabilities by 2026-03-10. CISA also urged all organizations to prioritize mitigation or discontinue use if mitigations were unavailable.

CISA adds four vulnerabilities to the KEV catalog

CISA updated its Known Exploited Vulnerabilities catalog on February 17, 2026, adding four CVEs: CVE-2008-0015, CVE-2020-7796, CVE-2024-7694, and CVE-2026-2441. The catalog version changed from 2026.02.13 to 2026.02.17 and the total listed vulnerabilities increased from 1518 to 1522.

Google fixes Chromium zero-day CVE-2026-2441 in Chrome 145.0.7632.75

Google released a fix for CVE-2026-2441 in Chrome versions prior to 145.0.7632.75, according to reporting on the KEV update. The patch addressed the actively exploited CSS use-after-free issue in Chromium.

Google discloses active exploitation of Chromium CVE-2026-2441

Google stated that an exploit for Chromium CSS use-after-free vulnerability CVE-2026-2441 exists in the wild. The flaw affects Chromium-based browsers and was described as an actively exploited zero-day.

Mar 1, 20251y ago

GreyNoise observes exploitation cluster targeting Zimbra SSRF flaw

GreyNoise reported a March 2025 exploitation cluster involving roughly 400 IP addresses targeting SSRF vulnerabilities, including Zimbra Collaboration Suite flaw CVE-2020-7796, across multiple countries. The activity provided evidence of in-the-wild exploitation later cited in reporting on the KEV addition.

Jan 8, 200818y ago

Microsoft documents exploitation of Windows Video ActiveX flaw CVE-2008-0015

Microsoft documented that CVE-2008-0015 in the Windows Video ActiveX Control was exploited to download additional malware and had been used to deliver the Dogkild worm. This establishes long-standing real-world exploitation of the flaw later added to CISA's KEV catalog.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Malware
1 linked
Affected products
13 linked
Threatsonar Anti-RansomwareZimbra Collaboration SuiteChromiumZimbra Collaboration Suite (Zcs)WindowsWebexInternet ExplorerOpera BrowserEdgeEdgeEdgeOperaChrome
Organizations
9 linked
ZimbraMicrosoft CorporationTeamt5GoogleThe Hacker NewsGreyNoiseBeyondtrustOperaSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.