---
reference_key: cisa-kev
title: "CISA Known Exploited Vulnerabilities Catalog"
url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
availability: available
capture_method: primary
captured_at: 2026-06-23T03:30:23Z
document_id: REF-cisa-kev
---

# CISA Known Exploited Vulnerabilities Catalog

| Field | Value |
|-------|-------|
| **Reference key** | `cisa-kev` |
| **Availability** | AVAILABLE |
| **Capture method** | `primary` |
| **Source type** | remote_url |
| **URL / path** | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| **Captured (UTC)** | 2026-06-23T03:30:23Z |
| **Content type** | text/html; charset=UTF-8 |
| **HTTP status** | 200 |

## Boardroom Citation Context

MVAP P7-01 daily KEV sweep; P7-10 patch SLA trigger.

## Source Location

https://www.cisa.gov/known-exploited-vulnerabilities-catalog





## Captured Content

```text
Known Exploited Vulnerabilities Catalog | CISA Skip to main content An official website of the United States government Heres how you know Heres how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means youve safely connected to the .gov website. Share sensitive information only on official, secure websites. Staying Secure at Events no-cost Cyber Services Secure by design Secure Your Business Report A Cyber Issue Search Menu Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? Government Educational Institutions Industry State, Local, Tribal, and Territorial Individuals and Families Small and Medium Businesses Find Help Locally Faith-Based Community Executives High-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Events no-cost Cyber Services Secure by design Secure Your Business Report A Cyber Issue Breadcrumb Home Known Exploited Vulnerabilities Catalog Share: Filters What are you looking for? (optional) Date Added (optional) Last 30 Days Last 60 Days Last 90 Days Last Year CVE (optional) Sort by (optional) Date Added Due Date Vendor/Project A-Z Items per page (optional) 20 - All - Leave this field blank (optional) Vendor/Project Accellion Craft CMS Gladinet Broadcom Qlik ConnectWise CrushFTP OSGeo BeyondTrust SimpleHelp Langflow TeleMessage ASUS Sangoma Dassault Systemes SmarterTools Check Point ServiceNow Dahua Versa PTZOptics CyberPersons Array Networks Cleo Reolink NUUO Paessler Hitachi Vantara Advantive Commvault GeoVision Wing FTP Server N-able OpenPLC BerriAI LiteSpeed Unitronics FXC Spreadsheet::ParseExcel Joomla! Sunhillo Nice NextGen Healthcare Justice AV Solutions PHP Group Twilio Acronis Kingsoft ScienceLogic Nostromo Metabase North Grid ProjectSend Acclaim Systems JQuery Audinate 7-Zip Trimble tj-actions NAKIVO Edimax reviewdog Qualitia Yiiframework FreeType ZKTeco Srimax MDaemon Erlang Wazuh AMI Looking Glass Git Libraesva Adminer Smartbedded SKYSEA IGEL Motex XWiki Meta Sierra Wireless Digiever Hewlett Packard Enterprise (HPE) Gogs Vite Prettier React Native Community Notepad++ TeamT5 Soliton Systems K.K Rockwell Omnissa n8n Aquasecurity TrueConf Marimo WebPros Nx TanStack Daemon Mirasvit Arista Widget Factory Splunk ownCloud Adobe Alcatel Amcrest Android Apache Apple Arcadyan Arcserve Arm Artifex Atlassian Aviatrix Barracuda Networks BQE Cacti ChakraCore Checkbox Cisco Citrix Code Aurora Crestron CWP D-Link D-Link and TRENDnet Dasan Dell Delta Electronics Docker dotCMS DotNetNuke (DNN) DrayTek Drupal Elastic Embedthis Exim EyesOfNetwork F5 FatPipe ForgeRock Fortinet Fortra Fuel CMS GIGABYTE GitLab GNU Google Grafana Labs Grandstream Hewlett Packard (HP) Hikvision IBM IETF Ignite Realtime ImageMagick InduSoft Intel Ivanti Jenkins JetBrains Juniper Kaseya Kentico Laravel LG Liferay Linux McAfee MediaTek Meta Platforms Micro Focus Microsoft MikroTik MinIO Mitel MongoDB Mozilla Nagios NETGEAR Netis Netwrix Novi Survey Npm package October CMS OpenBSD OpenSSL Oracle Palo Alto Networks PaperCut PEAR Perl PHP phpMyAdmin PHPUnit Pi-hole PlaySMS Plex Primetek Progress Pulse Secure QNAP QNAP Systems Qualcomm Quest Rails RARLAB rConfig Realtek Red Hat Redis Rejetto Roundcube Ruckus Wireless SaltStack Samba Samsung SAP Schneider Electric Siemens SIMalliance Sitecore SolarView SolarWinds Sonatype SonicWall Sophos Sudo SugarCRM Sumavision Symantec Synacor SysAid TeamViewer Teclib Telerik Tenda TerraMaster ThinkPHP TIBCO TP-Link Treck TCP/IP stack Trend Micro Trihedral TVT Ubiquiti Unraid vBulletin Veeam Veritas VMware VMware Tanzu WatchGuard WebKitGTK Webmin WebRTC WordPress WSO2 XStream Yealink Zabbix ZK Framework Zoho Zyxel No result Reset Known Exploited Vulnerabilities Catalog For the benefit of the cybersecurity community and network defenders---and to help every organization better manage vulnerabilities and keep pace with threat activity---CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about how to use the KEV catalog in your organization. Are you aware of an actively exploited vulnerability not included in the KEV Catalog? NOMINATE A NEW KEV The KEV catalog is also available in these formats: CSV JSON Print View JSON Schema (updated 06-25-2024) License Showing 1 - 20 of 1623 Splunk | Enterprise CVE-2026-20253 Splunk Enterprise Missing Authentication for Critical Function Vulnerability: Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. Related CWE: CWE-306 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-18 Due Date: 2026-06-21 Additional Notes https://advisory.splunk.com/advisories/SVD-2026-0603 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20253 Widget Factory | Joomla Content Editor CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability: Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. Related CWE: CWE-284 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-16 Due Date: 2026-06-19 Additional Notes https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites ; https://www.joomlacontenteditor.net/support/changelog/editor ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48907 Cisco | Catalyst SD-WAN Manager CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability: Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. Related CWE: CWE-22 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-15 Due Date: 2026-06-29 Additional Notes https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20262 LiteSpeed | cPanel Plugin CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability: LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Related CWE: CWE-61 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-15 Due Date: 2026-06-18 Additional Notes https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-54420 Oracle | PeopleSoft Enterprise PeopleTools CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability: Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. Related CWE: CWE-306 Known To Be Used in Ransomware Campaigns? Known Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-12 Due Date: 2026-06-15 Additional Notes https://www.oracle.com/security-alerts/alert-cve-2026-35273.html ; https://support.oracle.com/signin/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-35273 Ivanti | Sentry CVE-2026-10520 Ivanti Sentry OS Command Injection Vulnerability: Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. Related CWE: CWE-78 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAs BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAs Forensics Triage Requirements (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Date Added: 2026-06-11 Due Date: 2026-06-14 Additional Notes https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-10520 Cisco | Catalyst SD-WAN Manager CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability: Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. Related CWE: CWE-116 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-09 Due Date: 2026-06-23 Additional Notes https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx ; https://nvd.nist.gov/vuln/detail/CVE-2026-20245 Arista | Extensible Operating System CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability: Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. Related CWE: CWE-1023 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-09 Due Date: 2026-06-23 Additional Notes https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 ; https://nvd.nist.gov/vuln/detail/CVE-2026-7473 Google | Chromium V8 CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability: Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Related CWEs: CWE-787 | CWE-125 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-09 Due Date: 2026-06-23 Additional Notes https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html ; https://issues.chromium.org/issues/506689381 ; https://nvd.nist.gov/vuln/detail/CVE-2026-11645 Check Point | Security Gateway CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability: Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Related CWE: CWE-287 Known To Be Used in Ransomware Campaigns? Known Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-08 Due Date: 2026-06-11 Additional Notes https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM . ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751 BerriAI | LiteLLM CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability: BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host. Related CWEs: CWE-78 | CWE-77 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-08 Due Date: 2026-06-22 Additional Notes This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g ; https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable ; https://nvd.nist.gov/vuln/detail/CVE-2026-42271 SolarWinds | Serv-U CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability: SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. Related CWE: CWE-400 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-05 Due Date: 2026-06-19 Additional Notes https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 ; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7 ; https://nvd.nist.gov/vuln/detail/CVE-2026-28318 Mirasvit | Mirasvit Full Page Cache Warmer CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability: Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Related CWE: CWE-502 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-03 Due Date: 2026-06-06 Additional Notes https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247 Android | Framework CVE-2025-48595 Android Framework Integer Overflow Vulnerability: Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. Related CWE: CWE-190 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-02 Due Date: 2026-06-05 Additional Notes https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595 Linux | Kernel CVE-2022-0492 Linux Kernel Improper Authentication Vulnerability: Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. Related CWEs: CWE-287 | CWE-862 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-02 Due Date: 2026-06-05 Additional Notes This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af ; https://www.kernel.org/ ; https://nvd.nist.gov/vuln/detail/CVE-2022-0492 Oracle | WebLogic Server CVE-2024-21182 Oracle WebLogic Server Unspecified Vulnerability: Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-06-01 Due Date: 2026-06-04 Additional Notes https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182 Palo Alto Networks | PAN-OS CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability: Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. Related CWE: CWE-565 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-05-29 Due Date: 2026-06-01 Additional Notes https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257 Daemon | Daemon Tools Lite CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability: Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. Related CWE: CWE-506 Known To Be Used in Ransomware Campaigns? Unknown Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-05-27 Due Date: 2026-05-30 Additional Notes https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398 TanStack | TanStack CVE-2026-45321 TanStack Unspecified Vulnerability: TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Known To Be Used in Ransomware Campaigns? Known Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-05-27 Due Date: 2026-06-10 Additional Notes This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321 Nx | Nx Console CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability: Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Related CWE: CWE-506 Known To Be Used in Ransomware Campaigns? Known Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Date Added: 2026-05-27 Due Date: 2026-06-10 Additional Notes This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027 Currently on page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 ... Go to next page Next Go to last page Last Subscribe to the KEV Catalog Updates Stay up to date on the latest known exploited vulnerabilities. Subscribe Now Return to top Topics Spotlight Resources & Tools News & Events Careers About Cybersecurity & Infrastructure Security Agency Facebook X LinkedIn YouTube Instagram RSS CISA Central 1-844-Say-CISA contact@cisa.dhs.gov DHS Seal CISA.gov An official website of the U.S. Department of Homeland Security About CISA Budget and Performance DHS.gov FOIA Requests No FEAR Act Office of Inspector General Privacy Policy Subscribe The White House USA.gov Website Feedback
```

---

*Archived reference article for AICSR-STUDY-2026-001 footnote corpus.*
