Threat Intel
CISA Expands KEV Catalog with Four Fresh Exploited Vulnerabilities
CISA has added four newly confirmed, actively exploited CVEs to its Known Exploited Vulnerabilities (KEV) list, underscoring the urgency of patching exposed assets. The additions cover a Fortinet heap overflow, a Citrix NetScaler auth bypass, a Chromium V8 out‑of‑bounds write, and a Cisco Firewall Management Center auth bypass. Federal agencies are now required to prioritize rapid remediation of these high‑risk flaws, while all organizations are urged to follow a risk‑based approach to vulnerability management.
In a swift update to its KEV catalog, the Cybersecurity and Infrastructure Security Agency (CISA) has announced four new CVEs that are currently being exploited in the wild. These vulnerabilities span a range of high‑profile platforms and pose a direct threat to any exposed systems.
New KEV Additions
- CVE‑2025‑25249 – Heap‑based buffer overflow in multiple Fortinet products.
- CVE‑2026‑19490 – Authentication bypass in Citrix NetScaler via an alternate path or channel.
- CVE‑2026‑87491 – Out‑of‑bounds write in Google Chromium’s V8 engine.
- CVE‑2026‑20079 – Authentication bypass in Cisco Firewall Management Center through an alternate path or channel.
These flaws are not just theoretical; attackers are actively exploiting them to gain full control over vulnerable systems. The inclusion of these CVEs in the KEV catalog signals that they meet CISA’s strict criteria: evidence of active exploitation, a publicly available CVE ID, and clear mitigation guidance.
BOD 26‑04: Federal Prioritization Rules
Under Binding Operational Directive 26‑04, Federal Civilian Executive Branch agencies must prioritize patching of KEV‑listed vulnerabilities on publicly exposed assets that could grant an attacker total control. The directive also mandates that agencies verify whether a system has already been compromised before applying a patch.
While BOD 26‑04 applies only to FCEB agencies, CISA strongly encourages all organizations—public and private—to adopt a risk‑based approach and focus remediation on KEV catalog entries.
What to Do Next
- Check your inventory for any of the four new CVEs and apply the vendor‑provided patches immediately.
- Validate that no compromise has occurred prior to patch deployment.
- If you encounter an exploited vulnerability not yet in the KEV catalog, submit it via CISA’s KEV Nomination Form.
By staying on top of these newly catalogued threats, organizations can reduce the window of exposure and protect critical assets from active exploitation.