Skip to main content
Mallory
Back to intelligence
government-vulnerability-catalogactively-exploited-vulnerabilityperimeter-device-exposuregovernment-diplomatic-threat

CISA Orders Hunt for Cisco Device Compromise as New Exploited CVEs Mount

Updated 7d agoFirst seen May 25, 202660 sources

CISA issued Emergency Directive 25-03 ordering federal civilian agencies to identify and mitigate potential compromise of Cisco devices, then followed with supplemental guidance covering core-dump collection and threat-hunting steps. The directive indicates concern that Cisco infrastructure may already have been breached and requires agencies to validate device integrity, investigate for signs of compromise, and take remediation actions to reduce ongoing risk.

At the same time, CISA continued expanding its Known Exploited Vulnerabilities catalog with numerous newly listed flaws, including CVE-2026-33634, CVE-2026-5281, CVE-2026-32201, CVE-2026-3502, CVE-2026-33017, CVE-2026-20131, CVE-2026-3909, CVE-2026-1603, CVE-2026-21385, CVE-2026-22719, CVE-2026-2441, and CVE-2026-1281, alongside older but still exploited issues such as CVE-2025-40551, CVE-2025-20393, CVE-2025-15556, CVE-2024-43468, CVE-2023-48788, CVE-2021-44529, and CVE-2021-39935. The combined actions show U.S. authorities escalating warnings that active exploitation is broadening across enterprise technologies, with network appliances, email platforms, and internet-facing systems remaining priority targets for defenders.

Share:
CISA Orders Hunt for Cisco Device Compromise as New Exploited CVEs Mount
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

31 events from the most recent confirmed update back to the earliest known activity.

31 EVENTS
May 22, 202611d ago

CISA adds CVE-2026-20963 to the KEV catalog

CISA published a Known Exploited Vulnerabilities catalog entry or search-indexed listing for CVE-2026-20963, indicating the vulnerability was known to be exploited in the wild. The addition elevated the urgency of remediation for affected organizations, especially federal agencies.

Known Exploited Vulnerabilities Catalog | CISA

CISA adds CVE-2025-68613 to the KEV catalog

CISA published a Known Exploited Vulnerabilities catalog entry or search-indexed listing for CVE-2025-68613, indicating the vulnerability was known to be exploited. The publication elevated remediation priority for affected organizations, particularly federal agencies.

Known Exploited Vulnerabilities Catalog | CISA

CISA refreshes multiple KEV catalog entries and search pages

CISA published or refreshed multiple KEV search-result pages for previously listed CVEs, including CVE-2026-32201, CVE-2025-60710, CVE-2026-3502, CVE-2026-33017, CVE-2026-20131, CVE-2025-32432, CVE-2025-31277, CVE-2025-43510, CVE-2025-43520, CVE-2023-48788, CVE-2021-44529, CVE-2026-3909, CVE-2026-1603, CVE-2026-21385, CVE-2026-22719, CVE-2026-2441, CVE-2025-15556, CVE-2024-43468, CVE-2026-1281, CVE-2021-39935, and CVE-2025-20393. Based on the provided data, these are catalog/search refreshes and do not provide enough detail to separate them into distinct real-world incident events.

May 15, 202618d ago

CISA adds CVE-2025-26399 search-indexed KEV update

CISA republished or refreshed catalog search results for CVE-2025-26399 on its KEV site. This appears to be a site indexing or search update rather than a distinct new exploitation event.

Apr 23, 20261mo ago

CISA updates ED 25-03 with version 1 guidance on Cisco compromise

CISA published Version 1 of ED 25-03, continuing guidance to identify and mitigate potential compromise of Cisco devices. The updated directive indicated an ongoing federal response and refined mitigation expectations.

Apr 1, 20262mo ago

CISA adds CVE-2026-5281 to the KEV catalog

CISA added CVE-2026-5281 to the Known Exploited Vulnerabilities catalog. The listing reflected active exploitation and increased urgency for remediation.

Mar 26, 20262mo ago

CISA adds CVE-2026-33634 to the KEV catalog

CISA published a KEV entry for CVE-2026-33634, indicating the vulnerability was known to be exploited. The addition required prompt mitigation by affected entities.

Mar 9, 20263mo ago

CISA adds CVE-2025-26399 to the KEV catalog

CISA added CVE-2025-26399 to its KEV catalog, identifying it as actively exploited. The publication elevated the vulnerability's remediation priority.

Mar 5, 20263mo ago

HHS settles HIPAA investigation over MMG Fusion breach affecting 15 million

HHS' Office for Civil Rights announced a settlement of its HIPAA investigation into MMG Fusion, LLC following a breach affecting 15 million individuals. The action represented a regulatory resolution tied to a large healthcare data breach.

Feb 25, 20263mo ago

CISA adds CVE-2026-20127 to the KEV catalog

CISA published a Known Exploited Vulnerabilities entry for CVE-2026-20127. The listing reflected confirmed exploitation and prompted prioritization of defensive action.

Feb 13, 20264mo ago

CISA adds CVE-2026-1731 to the KEV catalog

CISA added CVE-2026-1731 to the KEV catalog, indicating the vulnerability had been exploited. The entry made the flaw subject to heightened remediation urgency.

Feb 5, 20264mo ago

CISA adds CVE-2025-11953 to the KEV catalog

CISA published a KEV entry for CVE-2025-11953, identifying it as a known exploited flaw. The addition signaled that affected organizations should prioritize mitigation.

CISA adds CVE-2026-24423 to the KEV catalog

CISA added CVE-2026-24423 to the Known Exploited Vulnerabilities catalog. The listing indicated exploitation in the wild and required accelerated remediation attention.

Feb 3, 20264mo ago

CISA adds CVE-2025-40551 to the KEV catalog

CISA published a KEV listing for CVE-2025-40551, marking it as actively exploited. The catalog addition elevated patching priority for affected systems.

CISA adds CVE-2025-64328 to the KEV catalog

CISA added CVE-2025-64328 to its Known Exploited Vulnerabilities catalog. The entry signaled observed exploitation and the need for prompt mitigation.

Jan 26, 20264mo ago

CISA adds CVE-2026-23760 to the KEV catalog

CISA published a KEV entry for CVE-2026-23760, indicating the flaw was known to be exploited. The addition placed the vulnerability into federal remediation workflows.

Jan 8, 20265mo ago

CISA republishes ED 21-01 on SolarWinds Orion compromise as closed

CISA published the closed version of Emergency Directive 21-01 concerning mitigation of the SolarWinds Orion code compromise. This reflected archival or status-updated publication of the directive on CISA's site.

Jan 7, 20265mo ago

CISA adds CVE-2025-37164 to the KEV catalog

CISA added CVE-2025-37164 to the KEV catalog, identifying it as a known exploited vulnerability. The listing increased urgency for patching and mitigation among affected organizations.

Dec 27, 20255mo ago

FBI warns Silent Ransom Group is targeting law firms

The FBI published an alert stating that the Silent Ransom Group was targeting law firms. The warning represented a law enforcement notification to a specific sector about an active threat campaign.

Dec 16, 20256mo ago

CISA adds CVE-2025-59718 to the KEV catalog

CISA published a Known Exploited Vulnerabilities catalog entry for CVE-2025-59718, indicating the vulnerability was known to be exploited in the wild. The addition elevated the urgency of remediation for affected organizations, especially federal agencies.

Known Exploited Vulnerabilities Catalog | CISA
Oct 24, 20257mo ago

CISA adds CVE-2025-54236 to the KEV catalog

CISA published a Known Exploited Vulnerabilities entry for CVE-2025-54236. The addition indicated active exploitation and triggered prioritization for mitigation.

Sep 25, 20258mo ago

CISA publishes supplemental core dump and hunt guidance for ED 25-03

CISA released a supplemental direction to ED 25-03 providing core dump collection and threat hunting instructions. The update expanded the government's response guidance for investigating suspected Cisco device compromise.

CISA issues ED 25-03 on potential compromise of Cisco devices

CISA published Emergency Directive 25-03 instructing agencies to identify and mitigate potential compromise affecting Cisco devices. The directive reflected concern that impacted devices may already have been compromised and required immediate defensive action.

May 19, 20251y ago

CISA adds CVE-2025-4428 to the KEV catalog

CISA added CVE-2025-4428 to the KEV catalog, signaling that exploitation had been observed in the wild. The listing made the vulnerability a priority for federal remediation timelines.

Oct 9, 20242y ago

CISA adds CVE-2024-23113 to the KEV catalog

CISA added CVE-2024-23113 to the Known Exploited Vulnerabilities catalog. The entry indicated the flaw was being exploited and should be remediated on an accelerated basis.

Aug 15, 20242y ago

CISA adds CVE-2024-28986 to the KEV catalog

CISA published a KEV entry for CVE-2024-28986, identifying it as a vulnerability under active exploitation. The addition required heightened patching priority for impacted systems.

Mar 13, 20242y ago

HHS opens OCR investigation into Change Healthcare cyberattack

HHS' Office for Civil Rights announced it had issued a letter and opened an investigation into the Change Healthcare cyberattack. The action signaled federal scrutiny of potential HIPAA-related impacts from the incident.

Feb 9, 20242y ago

CISA adds CVE-2024-21762 to the KEV catalog

CISA added CVE-2024-21762 to its Known Exploited Vulnerabilities catalog, reflecting confirmed exploitation activity. The listing elevated urgency for remediation across affected organizations, especially federal agencies.

Jan 1, 20233y ago

CISA publishes guidance for Citrix Bleed vulnerability

CISA published guidance addressing CVE-2023-4966, known as Citrix Bleed, affecting Citrix NetScaler ADC and Gateway devices. The guidance provided mitigation direction for organizations responding to the actively exploited vulnerability.

Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix Bleed | CISA
Feb 10, 20224y ago

CISA adds CVE-2020-0796 to the KEV catalog

CISA published a Known Exploited Vulnerabilities catalog entry for CVE-2020-0796, indicating the vulnerability was known to be exploited in the wild. Federal agencies would be expected to prioritize remediation under KEV requirements.

Sep 13, 20179y ago

CISA orders removal of Kaspersky-branded products from federal systems

CISA issued Binding Operational Directive 17-01 directing federal agencies to identify and remove Kaspersky-branded products from federal information systems. This marked a formal U.S. government mitigation action against the vendor's software in federal environments.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Orders Hunt for Cisco Device Compromise as New Exploited CVEs Mount | Mallory