Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogwidely-deployed-product-advisoryend-of-life-software

CISA Expands KEV Catalog With Broad Wave of Actively Exploited Enterprise Flaws

Updated 5d agoFirst seen Mar 11, 202637 sources

CISA repeatedly expanded its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation across a wide range of products, including Apple platforms, Ivanti EPM and EPMM, SolarWinds Web Help Desk, Omnissa Workspace ONE, n8n, Google Chromium and Skia, Wing FTP Server, Zimbra, Cisco firewall management products, Langflow, Aqua Security Trivy, F5 BIG-IP, Fortinet FortiClient EMS, Microsoft Exchange, SharePoint, Windows, Defender, Adobe Acrobat/Reader, Apache ActiveMQ, Trend Micro Apex One, Palo Alto PAN-OS, and other enterprise software. Several entries were especially notable because they involved remote code execution, code injection, deserialization, authentication bypass, privilege escalation, and supply-chain-style malicious code risks, while CISA also highlighted active exploitation of older legacy Microsoft and Adobe flaws that remain dangerous on unpatched or end-of-life systems.

Reporting tied some of the newly listed issues to concrete attack activity and elevated operational risk. Apple flaws added to KEV were reported as exploitable through malicious web content or apps and could lead to arbitrary code execution or kernel-level execution, while the critical Langflow bug CVE-2025-34291 was described as enabling session hijacking, token theft, persistence, and possible full system compromise in AI workflow deployments; separate reporting said the Iranian threat actor MuddyWater used it for initial access. Trend Micro said it observed at least one attempted in-the-wild exploitation of its Apex One flaw, and coverage of Ivanti vulnerabilities warned that defenders should not rely solely on shared indicators of compromise. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were ordered to remediate each KEV-listed flaw by assigned deadlines, and CISA urged all organizations to apply vendor fixes or mitigations immediately and discontinue affected products if no mitigation is available.

Share:
CISA Expands KEV Catalog With Broad Wave of Actively Exploited Enterprise Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

30 events from the most recent confirmed update back to the earliest known activity.

30 EVENTS
Jun 9, 20266d ago

CISA adds Arista, Google, and Cisco flaws to KEV catalog

On June 9, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-7473 in Arista Extensible Operating System, CVE-2026-11645 in Google Chromium V8, and CVE-2026-20245 in Cisco Catalyst SD-WAN Manager. CISA said the additions were based on evidence of active exploitation and urged organizations to prioritize remediation.

CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA
May 29, 202617d ago

CISA adds PAN-OS flaw CVE-2026-0257 to KEV

On May 29, 2026, CISA added CVE-2026-0257, an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS, to the KEV catalog based on evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 26, 202620d ago

CISA adds LiteSpeed cPanel Plugin flaw CVE-2026-48172 to KEV

On May 26, 2026, CISA added CVE-2026-48172, a LiteSpeed cPanel Plugin privilege escalation vulnerability, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 22, 202624d ago

Ctrl-Alt-Intel reports MuddyWater exploited Langflow flaw

In March 2026, Ctrl-Alt-Intel reported that the Iranian threat actor MuddyWater exploited Langflow vulnerability CVE-2025-34291 for initial access. This linked a specific threat actor to real-world exploitation of the flaw later added to CISA's KEV catalog.

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
May 21, 202625d ago

CISA adds Langflow and Trend Micro Apex One flaws to KEV

On May 21, 2026, CISA added CVE-2025-34291, a Langflow origin validation error vulnerability, and CVE-2026-34926, a Trend Micro Apex One on-premise directory traversal vulnerability, to the KEV catalog after determining there was evidence of active exploitation. Multiple reports noted the Langflow flaw could enable session hijacking, token theft, and potentially arbitrary code execution, while Trend Micro said it had observed at least one attempted in-the-wild exploitation of the Apex One issue.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
May 20, 202626d ago

CISA adds seven Microsoft and Adobe vulnerabilities to KEV

On May 20, 2026, CISA added seven actively exploited vulnerabilities affecting Microsoft Windows, Microsoft DirectX, Adobe Acrobat and Reader, Microsoft Internet Explorer, and Microsoft Defender to the KEV catalog. The set included legacy flaws from 2008 through 2010 as well as two 2026 Microsoft Defender vulnerabilities.

CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA
May 15, 20261mo ago

CISA adds Microsoft Exchange flaw CVE-2026-42897 to KEV

On May 15, 2026, CISA added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to the KEV catalog based on evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 8, 20261mo ago

CISA adds LiteLLM SQL injection flaw CVE-2026-42208 to KEV

On May 8, 2026, CISA added CVE-2026-42208, a SQL injection vulnerability affecting BerriAI LiteLLM, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 7, 20261mo ago

CISA adds Ivanti EPMM flaw CVE-2026-6973 to KEV

On May 7, 2026, CISA added CVE-2026-6973, an improper input validation vulnerability affecting Ivanti Endpoint Manager Mobile, to the KEV catalog based on active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
May 1, 20262mo ago

CISA adds Linux Kernel flaw CVE-2026-31431 to KEV

On May 1, 2026, CISA added CVE-2026-31431, a Linux Kernel incorrect resource transfer between spheres vulnerability, to the KEV catalog after obtaining evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 24, 20262mo ago

CISA adds four vulnerabilities affecting Samsung, SimpleHelp, and D-Link

On April 24, 2026, CISA added four vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and the D-Link DIR-823X to the KEV catalog. The flaws included path traversal, missing authorization, and command injection issues under active exploitation.

CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA
Apr 23, 20262mo ago

CISA adds Marimo flaw CVE-2026-39987 to KEV

On April 23, 2026, CISA added CVE-2026-39987, a Marimo remote code execution vulnerability, to the KEV catalog based on evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 22, 20262mo ago

CISA adds Microsoft Defender flaw CVE-2026-33825 to KEV

On April 22, 2026, CISA added CVE-2026-33825, a Microsoft Defender insufficient granularity of access control vulnerability, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 20, 20262mo ago

CISA adds eight exploited vulnerabilities across six products to KEV

On April 20, 2026, CISA added eight vulnerabilities affecting PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra Collaboration Suite, and Cisco Catalyst SD-WAN Manager to the KEV catalog. CISA said the additions were based on evidence of active exploitation.

CISA Adds Eight Known Exploited Vulnerabilities to Catalog | CISA
Apr 16, 20262mo ago

CISA adds Apache ActiveMQ flaw CVE-2026-34197 to KEV

On April 16, 2026, CISA added CVE-2026-34197, an Apache ActiveMQ improper input validation vulnerability, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 14, 20262mo ago

CISA adds Microsoft Office and SharePoint flaws to KEV

On April 14, 2026, CISA added CVE-2009-0238, a Microsoft Office remote code execution flaw, and CVE-2026-32201, a Microsoft SharePoint Server improper input validation vulnerability, to the KEV catalog.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
Apr 13, 20262mo ago

CISA adds seven exploited vulnerabilities across Microsoft, Adobe, and Fortinet

On April 13, 2026, CISA added seven new vulnerabilities to the KEV catalog affecting Microsoft Visual Basic for Applications, Adobe Acrobat, Microsoft Exchange Server, Microsoft Windows, Fortinet products, and Adobe Acrobat and Reader. The agency said all seven had evidence of active exploitation.

CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA
Apr 8, 20262mo ago

CISA adds Ivanti EPMM flaw CVE-2026-1340 to KEV

On April 8, 2026, CISA added CVE-2026-1340, a code injection vulnerability affecting Ivanti Endpoint Manager Mobile, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 6, 20262mo ago

CISA adds Fortinet FortiClient EMS flaw CVE-2026-35616 to KEV

On April 6, 2026, CISA added CVE-2026-35616, an improper access control vulnerability affecting Fortinet FortiClient EMS, to the KEV catalog based on active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Apr 1, 20263mo ago

CISA adds Google Dawn flaw CVE-2026-5281 to KEV

On April 1, 2026, CISA added CVE-2026-5281, a Google Dawn use-after-free vulnerability, to the KEV catalog after determining there was evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 27, 20263mo ago

CISA adds F5 BIG-IP flaw CVE-2025-53521 to KEV

On March 27, 2026, CISA added CVE-2025-53521, an F5 BIG-IP remote code execution vulnerability, to the KEV catalog after obtaining evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 26, 20263mo ago

CISA adds Aqua Security Trivy flaw CVE-2026-33634 to KEV

On March 26, 2026, CISA added CVE-2026-33634, identified as an Aqua Security Trivy Embedded Malicious Code vulnerability, to the KEV catalog based on active exploitation evidence.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 25, 20263mo ago

CISA adds Langflow code injection flaw CVE-2026-33017 to KEV

On March 25, 2026, CISA added CVE-2026-33017, a Langflow code injection vulnerability, to the KEV catalog after obtaining evidence of active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 19, 20263mo ago

CISA adds Cisco firewall management flaw CVE-2026-20131 to KEV

On March 19, 2026, CISA added CVE-2026-20131 affecting Cisco Secure Firewall Management Center and Cisco Security Cloud Control Firewall Management to the KEV catalog. The flaw was described as a deserialization of untrusted data issue under active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 18, 20263mo ago

CISA adds Synacor Zimbra flaw CVE-2025-66376 to KEV

On March 18, 2026, CISA added CVE-2025-66376, a cross-site scripting vulnerability affecting Synacor Zimbra Collaboration Suite, to the KEV catalog based on active exploitation.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 16, 20263mo ago

CISA adds Wing FTP Server flaw CVE-2025-47813 to KEV

On March 16, 2026, CISA added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to the KEV catalog after evidence of active exploitation emerged.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 13, 20263mo ago

CISA adds two Google vulnerabilities to KEV

On March 13, 2026, CISA added CVE-2026-3909, a Google Skia out-of-bounds write flaw, and CVE-2026-3910, a Google Chromium V8 vulnerability, to the KEV catalog. The agency said both were being actively exploited.

CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
Mar 11, 20263mo ago

CISA adds n8n vulnerability CVE-2025-68613 to KEV

On March 11, 2026, CISA added CVE-2025-68613 affecting n8n to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. CISA described it as an improper control of dynamically managed code resources issue.

CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Mar 9, 20263mo ago

CISA adds Ivanti, SolarWinds, and Omnissa flaws to KEV catalog

On March 9, 2026, CISA added CVE-2026-1603 in Ivanti Endpoint Manager, CVE-2025-26399 in SolarWinds Web Help Desk, and CVE-2021-22054 in Omnissa Workspace ONE to the KEV catalog based on active exploitation. The listed issues included authentication bypass, deserialization-based remote code execution, and server-side request forgery.

CISA KEV Catalog Update - March 9 2026 - TheCyberThrone
Mar 5, 20263mo ago

CISA adds three Apple vulnerabilities to KEV catalog

On March 5, 2026, CISA added three actively exploited Apple vulnerabilities affecting macOS, iOS, iPadOS, Safari, and related platforms to its Known Exploited Vulnerabilities catalog. The flaws included two use-after-free issues and one integer overflow issue that could lead to memory corruption, arbitrary code execution, or kernel-privileged code execution.

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

127 LINKEDOpen in app
Vulnerabilities
60 linked
Authentication Bypass in Palo Alto PAN-OS GlobalProtectMS08-067 Windows Server Service Buffer OverflowMicrosoft DirectX NULL Byte Overwrite VulnerabilityMicrosoft Internet Explorer HTML Object Memory Corruption VulnerabilityAdobe Acrobat and Reader Heap-Based Buffer OverflowMicrosoft Internet Explorer Peer Objects Use-After-Free RCELangflow Origin Validation Error Account Takeover and RCEUnDefendRedSun: Microsoft Defender Link-Following Privilege EscalationDirectory Traversal in Trend Micro Apex One (On-Premise)Authentication Bypass in PaperCut NG/MF SecurityRequestFilterAuthenticated Path Traversal and Arbitrary File Upload RCE in Kentico Xperience Staging Sync ServerVisual Basic for Applications Insecure Library Loading VulnerabilityApple Multiple Products Integer Overflow or Wraparound VulnerabilityIvanti EPMM Remote Unauthenticated API Access Authentication BypassOmnissa Workspace ONE UEM Server-Side Request ForgeryPath Traversal in Samsung MagicINFO 9 ServerPrivilege Escalation in Host Process for Windows TasksMicrosoft Exchange Server Deserialization of Untrusted Data RCESimpleHelp Missing Authorization Privilege EscalationUse-after-free RCE in Adobe AcrobatSimpleHelp Zip Slip Arbitrary File Upload Leading to RCEParallax kernel use-after-free in Apple iOS and iPadOSCommand Injection in D-Link DIR-823X /goform/set_prohibitingUnauthenticated AjaxProxy Deserialization RCE in SolarWinds Web Help DeskUnauthenticated RCE in F5 BIG-IP APM access policy processingAuthentication Bypass in Quest KACE Systems Management Appliance SSOSQL Injection RCE in Ivanti Endpoint Manager Core ServerWindows Common Log File System Driver Out-of-Bounds Read Privilege EscalationJetBrains TeamCity Relative Path Traversal Authentication BypassZero-click XSS in Zimbra Collaboration Classic UISolarWinds Web Help Desk AjaxProxy Java Deserialization RCEWebKit Use-After-Free in Apple Safari, iOS, iPadOS, and macOSUnauthenticated Java Deserialization RCE in SolarWinds Web Help Desk AjaxProxyRemote Code Execution in Microsoft Office Excel Malformed Object HandlingAuthenticated RCE in n8n Workflow Expression EvaluationStored XSS in Zimbra Collaboration Classic UI via CSS @import in HTML emailUnauthenticated RCE in Ivanti EPMM Android File Transfer mechanismUnauthenticated RCE in Ivanti Endpoint Manager Mobile In-House Application DistributionUnauthenticated SQL Injection RCE in Fortinet FortiClient EMSAuthentication Bypass in Ivanti Endpoint ManagerArbitrary File Overwrite in Cisco Catalyst SD-WAN Manager APICredential Disclosure in Cisco Catalyst SD-WAN Manager Data Collection AgentSensitive Information Exposure in Cisco Catalyst SD-WAN ManagerInappropriate implementation in V8 in Google ChromeOut-of-bounds write in Skia in Google ChromeUnauthenticated RCE in Langflow build_public_tmp Public Flow EndpointTrivy supply chain compromise via malicious release and retagged GitHub ActionsUse-after-free in Google Chrome Dawn (WebGPU)Authentication Bypass and RCE in Fortinet FortiClient EMSAuthenticated RCE in Apache ActiveMQ Classic Jolokia JMX-HTTP BridgePre-Auth RCE in Marimo /terminal/ws WebSocket EndpointAdobe Acrobat and Reader Prototype Pollution Arbitrary Code ExecutionBlueHammerMicrosoft SharePoint Server Spoofing VulnerabilityCopy FailPre-auth SQL Injection in BerriAI LiteLLM Proxy API Key VerificationRCE in Ivanti Endpoint Manager Mobile via Improper Input ValidationCross-Site Scripting in Microsoft Exchange Server Outlook Web AccessPrivilege Escalation in LiteSpeed User-End cPanel Plugin redisAble Function
Threat actors
2 linked
Affected products
34 linked
Pan-OsLangflowMicrosoft DefenderEndpoint Manager MobileZimbra Collaboration SuiteApex OneSimplehelpDir-823xKace Systems Management ApplianceFortinetMagicinfo 9 ServerWindowsXperienceTvosTeamcitySafariCatalyst SD-WAN ManagerIpadosInternet ExplorerAdobe ReaderDirectxBig-IpWatchosLinux KernelSkiaApache-ActivemqMicrosoft OfficeOracle Weblogic ServerLitellmN8nDefenderIosMacosForticlient Ems
Organizations
31 linked
Palo Alto NetworksMicrosoft CorporationAdobeTrend MicroIvantiGoogleCisco SystemsZimbraFortinetLitespeed TechnologiesQuest SoftwareGreyNoiseObsidian SecurityLinkedinPaperCut SoftwareSamsung ElectronicsSolarWindsD-LinkF5XAppleConnectwiseOmnissaSimpleHelpJetbrainsAqua SecurityKentico SoftwareLangflowSecurity AffairsBerriAICtrl-Alt-Intel
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Expands KEV Catalog With Broad Wave of Actively Exploited Enterprise Flaws | Mallory