discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.

By CISA·Sep 10·cisa.gov·1 min read

Intelligence analysis by Qwen 2.5 (3B)

CISA has added two vulnerabilities to its KEV Catalog, based on evidence of active exploitation, to help agencies prioritize security updates.

Why it matters

This update is crucial for federal agencies to ensure they are addressing the most critical vulnerabilities and to help prevent cyber attacks.

CISA is adding two new security problems to a list of known problems that can be used by bad guys. They want agencies to fix these problems quickly to keep their systems safe.

Analysis

{"heading":"Prioritizing Security Updates","subheading":"BOD 26-04: Prioritizing Security Updates Based on Risk","paragraph_1":"BOD 26-04 establishes vulnerability management requirements for FCEB agencies, emphasizing the importance of the KEV Catalog and the need to prioritize remediation of high-risk vulnerabilities.","paragraph_2":"The KEV Catalog is a key tool for agencies to identify and address vulnerabilities that could be exploited, and BOD 26-04 reinforces the need for agencies to follow these guidelines.","paragraph_3":"CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities, in addition to following BOD 26-04."}

Key points

  • CISA added two new vulnerabilities to its KEV Catalog
  • These vulnerabilities are based on evidence of active exploitation
  • BOD 26-04 requires federal agencies to prioritize remediation of high-risk vulnerabilities
  • CISA encourages all organizations to adopt risk-based vulnerability management
The Upside

By adding these vulnerabilities to the KEV Catalog, agencies can better prioritize their security work and protect against potential attacks.

The Downside

If agencies do not address these vulnerabilities quickly, they could be vulnerable to attacks that exploit these security problems.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecuritycisavulnerabilitieskev-catalog

Author

CISA

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 10, 2026

Source

cisa.gov

Share

Topics

securitycisavulnerabilitieskev-catalog

Related

More from this desk

Oct 7·bleepingcomputer.com

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud CEO charged with fraud for secretly paying ransomware attackers, charging victims up to $19 million for recovery services.

Oct 7·wired.com

Shaq Got Hacked. Now He’s Pitching for a VPN

Shaq talks about his experience with cyber security and the importance of personal privacy. NordVPN is helping him raise awareness.

Oct 7·bleepingcomputer.com

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

Oct 7·bleepingcomputer.com

Hackers Hijack Google Domains After Breaching ccTLD Registries

Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.