CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. It urges organizations to prioritize remediation, especially federal civilian agencies under BOD 22-01.
Intelligence analysis by GPT-5.4 Mini
CISA says three new CVEs have been added to its Known Exploited Vulnerabilities Catalog based on active exploitation: CVE-2026-8398 in Daemon Tools Lite, CVE-2026-45321 in TanStack, and CVE-2026-48027 in Nx Console. The agency frames these flaws as high-risk attack paths and tells organizations to patch them promptly.
CISA is like a safety referee for computers in the U.S. government. It just added three broken spots in software to its danger list because bad actors are already using them.
That matters because a broken lock on a door is more urgent when thieves are known to be trying the handle. The list helps teams know what to fix first.
CISA says government agencies must repair these problems by the deadline, and it asks other organizations to do the same kind of fast fixing.
Analysis
What CISA added
CISA says it added three vulnerabilities to its Known Exploited Vulnerabilities Catalog because there is evidence they are being actively exploited. The three entries are CVE-2026-8398 in Daemon Tools Lite, CVE-2026-45321 in TanStack, and CVE-2026-48027 in Nx Console.
Why the catalog matters
The KEV Catalog is described as a living list of CVEs that present significant risk to the federal enterprise. CISA points to Binding Operational Directive 22-01, which requires Federal Civilian Executive Branch agencies to remediate listed vulnerabilities by the due date. The practical point is simple: if a flaw is in KEV, it is no longer a theoretical issue.
Who should act
Although the directive formally applies to FCEB agencies, CISA “strongly urges” all organizations to use the catalog as part of vulnerability management and to prioritize timely remediation of KEV items. The agency also says it will continue adding vulnerabilities that meet the catalog’s criteria. For defenders, this is a reminder to check whether these products are present, assess exposure, and move remediation ahead of lower-risk findings.
Key points
- CISA added three CVEs to its Known Exploited Vulnerabilities Catalog based on active exploitation.
- The vulnerabilities affect Daemon Tools Lite, TanStack, and Nx Console.
- BOD 22-01 requires FCEB agencies to remediate cataloged vulnerabilities by the due date.
- CISA urges all organizations to prioritize KEV items in their vulnerability management.
- The agency says it will keep adding vulnerabilities that meet its criteria.



