discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.

By CISA·Aug 31·cisa.gov·1 min read

Intelligence analysis by Qwen 2.5 (3B)

CISA has added two vulnerabilities to its KEV Catalog based on evidence of active exploitation, including a PaperCut NG/MF authentication issue and an unsafe reflection vulnerability.

Why it matters

These vulnerabilities pose significant risks to federal enterprises and reinforce the importance of prioritizing security updates and risk-based vulnerability management.

CISA found two new problems in computer systems that could let bad guys do bad things. They added these problems to a list so people can be extra careful and fix them quickly.

Analysis

{"heading":"KEV Nomination Form","subheading":"Submitting Exploited Vulnerabilities","paragraph_1":"CISA encourages organizations to submit potential KEV additions through its KEV Nomination Form, which must include a CVE ID, evidence of exploitation, and clear mitigation guidance.","paragraph_2":"CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.","paragraph_3":"CISA will also consider potential KEV additions submitted through the nomination form."}

Key points

  • CISA added two new vulnerabilities to its KEV Catalog
  • CVE-2026-81578 and CVE-2026-82078 are the two vulnerabilities
  • BOD 26-04 requires federal agencies to prioritize the remediation of high-risk vulnerabilities
  • CISA encourages all organizations to adopt risk-based vulnerability management
  • CISA will continue to add vulnerabilities to the catalog that meet the specified criteria
The Upside

By adding these vulnerabilities to the catalog, CISA hopes to help federal agencies stay safer and more secure.

The Downside

If these vulnerabilities are not fixed quickly, they could let bad guys do even more damage to federal systems.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecurityfederal-enterprisevulnerability-managementrisk-based-vulnerability-managementcisa

Author

CISA

Intelligence analysis by

Qwen 2.5 (3B)

Published

Aug 31, 2026

Source

cisa.gov

Share

Topics

securityfederal-enterprisevulnerability-managementrisk-based-vulnerability-managementcisa

Related

More from this desk

Aug 31·bleepingcomputer.com

Cronos blockchain restarts after $74 million Tectonic exploit

Cronos blockchain network resumes trading after Tectonic exploit

Aug 31·bleepingcomputer.com

Microsoft Warns of TerminalFix Attacks Using Reverse Tunnels

Microsoft alerts about a new variant of ClickFix attacks that use fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attacks lead to a multi-stage intrusion chain resulting in a reverse tunnel into the vict…

Aug 31·schneier.com

Is Someone Hacking DoD Refrigerators?

DoD refrigerators affected in multiple bases. Pentagon officials declined to comment.

Aug 31·bleepingcomputer.com

Microsoft Exchange Online Outage Causes Email Failures, Authentication Issues

Microsoft investigating widespread service issue affecting Exchange Online users. Authentication, email delays, and failures reported.