Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogdefault-credential-exposurewidely-deployed-product-advisory

CISA Adds GitLab SSRF and Dell RP4VM Hard-coded Credentials to KEV Catalog

Updated 3mo agoFirst seen Feb 18, 20264 sources

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2021-22175 (a GitLab server-side request forgery (SSRF) issue related to enabling internal-network requests for webhooks) and CVE-2026-22769 (a Dell RecoverPoint for Virtual Machines (RP4VMs) vulnerability involving hard-coded credentials that can enable unauthenticated access to the underlying OS and root-level persistence). Under BOD 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to remediate by CISA’s specified due dates, and CISA urged all organizations to prioritize remediation of KEV-listed issues as part of vulnerability management.

CISA’s public KEV data repository was updated to reflect the new catalog release (catalog count increasing from 1522 to 1524) and to include the new entries with their remediation deadlines (GitLab due 2026-03-11; Dell RP4VMs due 2026-02-21). Separate commentary and guidance from industry media emphasized using KEV as a prioritization input rather than a blanket “panic list,” recommending teams weigh exploitability and impact context (e.g., access prerequisites, remote control potential) and combine KEV with other signals such as CVSS, EPSS, and exploit/tooling intelligence to drive patch sequencing.

Share:
CISA Adds GitLab SSRF and Dell RP4VM Hard-coded Credentials to KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 18, 20264mo ago

CISA sets federal remediation deadlines for the two KEV entries

Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the newly listed vulnerabilities by specific deadlines. Agencies were ordered to fix the Dell RecoverPoint flaw by 2026-02-21 and the GitLab flaw by 2026-03-11.

CISA adds GitLab and Dell flaws to the KEV catalog

On February 18, 2026, CISA added CVE-2021-22175, a GitLab SSRF vulnerability, and CVE-2026-22769, a Dell RecoverPoint for Virtual Machines hard-coded credentials flaw, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The KEV catalog total increased from 1522 to 1524 entries.

Dell releases fixes and mitigation guidance for CVE-2026-22769

Dell released patches and mitigation guidance for the hard-coded credentials flaw CVE-2026-22769 in RecoverPoint for Virtual Machines after receiving reports of limited active exploitation. The fix preceded CISA's later KEV action and federal remediation order.

Jun 15, 20242y ago

UNC6201 begins exploiting Dell RecoverPoint zero-day

Google Mandiant reported that suspected PRC-linked cluster UNC6201 had been exploiting Dell RecoverPoint for Virtual Machines vulnerability CVE-2026-22769 since at least mid-2024. The activity involved unauthorized access to VMware backup systems, lateral movement, persistence, and deployment of malware including SLAYSTYLE, BRICKSTORM, and GRIMBOLT.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Threat actors
2 linked
Affected products
5 linked
GitlabGoogle SearchVcenter ServerGrafanaGrafana
Organizations
11 linked
Dell TechnologiesGoogleGitLabThe RegisterBeyondtrustTP-LinkMicrosoft CorporationGreyNoiseZimbraBroadcomSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.