rootpwn

Threat Intel

CISA Expands KEV Catalog with Four New Exploited CVEs, Urges Rapid Patch Deployment

CISA has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) list, covering SonicWall SMA1000 appliances and Microsoft AD FS and SharePoint. The update reinforces BOD 26‑04’s mandate for federal agencies to prioritize patching high‑risk flaws and encourages all organizations to adopt risk‑based remediation and submit additional KEV candidates.

In a move to tighten federal cyber defenses, the Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) catalog by adding four CVEs that have been confirmed as actively exploited in the wild.

New KEV Additions

  • CVE‑2026‑15409 – Server‑Side Request Forgery in SonicWall SMA1000 appliances.
  • CVE‑2026‑15410 – Code injection flaw in SonicWall SMA1000 appliances.
  • CVE‑2026‑56155 – Insufficient granularity of access control in Microsoft Active Directory Federation Services.
  • CVE‑2026‑56164 – Missing authentication for a critical function in Microsoft SharePoint Server.

These vulnerabilities are particularly dangerous because they can grant attackers full control over the affected systems when left unpatched. CISA’s inclusion of these CVEs signals that they meet the agency’s criteria of “active exploitation” and “high‑risk impact.”

Implications for Federal Agencies

BOD 26‑04, “Prioritizing Security Updates Based on Risk,” requires Federal Civilian Executive Branch (FCEB) agencies to focus patching efforts on KEV-listed CVEs that expose publicly reachable assets. The directive also sets expectations for agencies to verify whether a system has been compromised before a patch is applied. While the directive is aimed at FCEB entities, CISA recommends that all organizations adopt a similar risk‑based approach and treat KEV vulnerabilities as top‑priority.

How to Keep Your Systems Safe

  • Review the KEV catalog regularly and ensure your patch management process addresses listed CVEs immediately.
  • Use automated scanning tools to detect unpatched SonicWall and Microsoft components.
  • Verify system integrity after patching to confirm that no exploitation has occurred.
  • Submit any newly discovered exploited vulnerabilities through CISA’s KEV Nomination Form, providing a CVE ID, exploitation evidence, and mitigation guidance.
“CISA will continue to add vulnerabilities that meet the active‑exploitation criteria,” said a CISA spokesperson. “We encourage organizations to stay vigilant and report potential KEV candidates.”

cisa kev vulnerabilities patching risk management sonicwall microsoft

← All news