CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added a new vulnerability, CVE-2026-45247, to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The agency urges all organizations to promptly remediate this and other KEV catalog vulnerabilities to mitigate cyberattack ri…
Intelligence analysis by Gemini 2.5 Flash
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its KEV Catalog by including a critical vulnerability, CVE-2026-45247, linked to Mirasvit Full Page Cache Warmer. This addition highlights the ongoing threat of actively exploited flaws and reinforces CISA's directive for federal agencies, and recommendation for all organizations, to patch these vulnerabilities t…
Imagine a secret code that helps bad guys sneak into computer systems. CISA, a government group that helps keep computers safe, just found a new secret code (called CVE-2026-45247) that bad guys are already using to break in. CISA tells all government computers to fix this code quickly, and they want everyone else with computers to fix it too, like patching a hole in a fence before a fox gets in.
Analysis
CISA has recently updated its Known Exploited Vulnerabilities (KEV) Catalog by including one new vulnerability: CVE-2026-45247. This specific vulnerability is identified as a "Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability." The agency explicitly states that this addition is "based on evidence of active exploitation," underscoring the immediate threat it presents.
The CISA alert highlights that this particular type of vulnerability serves as a "frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise." This designation means that such flaws are commonly targeted by attackers, making them high-priority concerns for cybersecurity defense.
The KEV Catalog itself was established under Binding Operational Directive (BOD) 22-01, titled "Reducing the Significant Risk of Known Exploited Vulnerabilities." This directive mandates that Federal Civilian Executive Branch (FCEB) agencies must remediate any vulnerabilities listed in the catalog by their specified due dates. This requirement is in place "to protect FCEB networks against active threats."
While BOD 22-01 is legally binding only for FCEB agencies, CISA issues a strong recommendation to all other organizations. The agency "strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice." This advice extends the call to action beyond federal entities, stressing that all public and private sector organizations should consider KEV entries as critical and address them promptly. CISA also affirmed its commitment to "continue to add vulnerabilities to the catalog that meet the specified criteria."
Key points
- CISA added CVE-2026-45247, a Mirasvit Full Page Cache Warmer vulnerability, to its KEV Catalog.
- The vulnerability is actively exploited by cyber actors and poses significant risks.
- Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV vulnerabilities under BOD 22-01.
- CISA strongly advises all organizations to prioritize patching KEV Catalog vulnerabilities.
- This type of deserialization vulnerability is a frequent attack vector.
By adding this vulnerability to the KEV Catalog and urging remediation, CISA is actively enhancing the collective cybersecurity posture. Organizations that promptly address CVE-2026-45247 can significantly reduce their attack surface and protect sensitive data from ongoing exploitation efforts, thereby minimizing potential breaches and maintaining operational integrity.
Despite CISA's clear directives, a significant number of organizations may fail to remediate this vulnerability in a timely manner, leaving their systems exposed. This could lead to widespread exploitation of CVE-2026-45247 by malicious actors, resulting in data breaches, system compromises, and substantial financial and reputational damages across various sectors.



