CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two actively exploited flaws to its KEV catalog, including issues in BerriAI LiteLLM and Check Point Security Gateway.
Intelligence analysis by GPT-5.4 Mini
The U.S. cyber agency expanded its Known Exploited Vulnerabilities list with two flaws already seen in the wild. The update pushes federal agencies to patch quickly and signals that other organizations should treat the bugs as urgent too.
CISA is like a safety guard for computers. It just put two risky holes on its warning list, telling people to fix them fast before burglars can use them like unlocked doors.
Analysis
What CISA added
CISA says it added two vulnerabilities to its Known Exploited Vulnerabilities Catalog after finding evidence that attackers are actively exploiting them. The two items are CVE-2026-42271, described as a command injection issue in BerriAI LiteLLM, and CVE-2026-50751, described as an improper authentication issue in Check Point Security Gateway.
Why the catalog matters
The KEV catalog is CISA’s running list of weaknesses that have been confirmed as dangerous in the real world. It exists to push defenders toward faster patching, not just theoretical risk management. In the alert, CISA notes that these kinds of vulnerabilities are a common way malicious actors get in.
What agencies are expected to do
CISA points to Binding Operational Directive 22-01, which requires Federal Civilian Executive Branch agencies to remediate listed vulnerabilities by the due date. The alert says that requirement is meant to protect federal networks from active threats.
Broader takeaway
Although the directive applies to federal civilian agencies, CISA explicitly urges all organizations to prioritize KEV-listed issues as part of normal vulnerability management. That makes this update relevant beyond government: if a flaw is on the KEV list, defenders should assume attackers may already be working it.
Key points
- CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog on June 8, 2026.
- The listed flaws affect BerriAI LiteLLM and Check Point Security Gateway.
- CISA says there is evidence the vulnerabilities are being actively exploited.
- Federal civilian agencies must remediate KEV-listed vulnerabilities by the required due date under BOD 22-01.
- CISA urges all organizations to prioritize KEV items in their vulnerability management programs.
If organizations move quickly, the catalog update can help them focus on the most urgent fixes first. That can reduce the chance that these already-exploited flaws are used to break into more systems.
If teams delay patching, the same active exploitation CISA is warning about could continue spreading. Systems that stay unpatched may remain easy targets for attackers looking for known entry points.



