rootpwn

Threat Intel

CISA Expands KEV Catalog with Four Freshly Exploited CVEs

The Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) list by adding four CVEs that are currently being abused in the wild. The new entries target Fortinet, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center, all of which can grant attackers full control over exposed systems. Federal agencies are urged to prioritize patching these high‑risk flaws under BOD 26‑04, while the broader community is encouraged to adopt a risk‑based remediation strategy and submit additional exploited CVEs for consideration.

CISA’s latest update to the KEV Catalog underscores the relentless pace at which attackers are turning known weaknesses into active threats. Four new CVEs have been added based on confirmed exploitation evidence:

  • CVE‑2025‑25249 – Heap‑based buffer overflow in multiple Fortinet products.
  • CVE‑2026‑19490 – Authentication bypass in Citrix NetScaler via an alternate path or channel.
  • CVE‑2026‑87491 – Out‑of‑bounds write in Google Chromium’s V8 engine.
  • CVE‑2026‑20079 – Authentication bypass in Cisco Firewall Management Center, also via an alternate path or channel.

These vulnerabilities represent classic attack vectors that can grant attackers full control of the affected assets. Under Binding Operational Directive (BOD) 26‑04, federal civilian executive branch agencies must prioritize rapid remediation of KEV-listed CVEs on publicly exposed systems that could lead to total control after exploitation.

"The KEV Catalog is a critical tool for prioritizing security updates. Agencies must act swiftly on high‑risk vulnerabilities and verify whether systems have been compromised before applying patches," said the directive.

While BOD 26‑04 applies specifically to federal agencies, CISA urges every organization to adopt a risk‑based vulnerability management approach and focus on KEV catalog entries. CISA will continue to add CVEs that meet its criteria, and it welcomes submissions of newly exploited vulnerabilities through its KEV Nomination Form. Potential additions must include a CVE ID, evidence of exploitation, and clear mitigation guidance.

CISA KEV Fortinet Citrix Google Cisco Vulnerability

← All news