CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog. The agency urged organizations to prioritize remediation, especially federal civilian agencies.
Intelligence analysis by GPT-5.4 Mini
CISA says it has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog after finding evidence of active exploitation: CVE-2022-0492 in the Linux kernel and CVE-2025-48595 in Android Framework. The agency frames both as high-priority risks and tells organizations to remediate them quickly.
CISA found two software bugs that bad actors are already trying to use, so it put them on a special danger list. It is like marking two broken locks with a red sticker so everyone fixes them first.
Analysis
What CISA added
CISA says it added two vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence that they are being actively exploited. The entries are CVE-2022-0492, described as a Linux kernel improper authentication vulnerability, and CVE-2025-48595, described as an Android Framework integer overflow vulnerability.
Why the catalog matters
The KEV Catalog exists under Binding Operational Directive 22-01, which CISA says created a living list of CVEs that present significant risk to the federal enterprise. Under that directive, Federal Civilian Executive Branch agencies are required to remediate identified vulnerabilities by the due date.
CISA also extends the warning beyond federal agencies. It says that although the directive only applies to FCEB agencies, all organizations should reduce exposure to cyberattacks by prioritizing timely remediation of KEV-listed issues as part of normal vulnerability management. The agency says it will keep adding vulnerabilities that meet the catalog criteria.
The practical message is straightforward: these are not theoretical bugs. CISA is treating them as active-threat items, which makes patching, mitigation, and asset inventory more urgent than usual.
Key points
- CISA added two vulnerabilities to the KEV Catalog after finding evidence of active exploitation.
- The new entries are CVE-2022-0492 in the Linux kernel and CVE-2025-48595 in Android Framework.
- CISA says these vulnerabilities are a frequent attack vector and pose significant risk to the federal enterprise.
- Federal civilian agencies must remediate KEV-listed vulnerabilities by the required due date under BOD 22-01.
- CISA urges all organizations to prioritize remediation as part of vulnerability management.
If organizations act on the catalog quickly, they can close off two known attack paths before more systems are hit. The directive also gives federal agencies a clear remediation target, which can improve coordination and accountability.
If patches are delayed, attackers may keep exploiting the two flaws in Linux and Android environments. Organizations that do not track KEV-listed issues closely could leave widely used systems exposed longer than necessary.



