CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
ID: 722bcd95-64aa-50f3-b778-c762118fc033
STIX ID: report--722bcd95-64aa-50f3-b778-c762118fc033
Feed Name: The Hacker News
CISA added eight vulnerabilities to its Known Exploited Vulnerabilities catalog — including three affecting Cisco Catalyst SD-WAN Manager — citing evidence of in-the-wild exploitation. The listed CVEs range from authentication bypass and path traversal to credential exposure (one with CVSS 10.0), with prior attribution of exploitation (CVE-2023-27351 to Lace Tempest linked to Cl0p/LockBit) and recent observations of weaponization by unknown actors (CVE-2025-32975). Cisco and other vendors acknowledge active abuse of several flaws; FCEB agencies were given near-term remediation deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
