International Edition
Latest News
Technology

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Updates Known Exploited Vulnerabilities Catalog - What Organizations need to KnowTable of ContentsCISA Updates Known Exploited Vulnerabilities Catalog - What Organizations need to KnowUnderstanding the KEV CatalogRecent Additions and associated RisksWho Needs to Take Action?Key Steps for…

CISA Updates Known Exploited Vulnerabilities Catalog – What Organizations need to Know

Table of Contents

Published: 2026/01/08 13:13:37

The Cybersecurity and infrastructure Security Agency (CISA) continuously works to safeguard the nation’s digital infrastructure. A core component of this effort is maintaining the [[1]] Known Exploited Vulnerabilities (KEV) Catalog, a regularly updated list of vulnerabilities actively exploited by malicious actors. On January 8, 2026, CISA added two new vulnerabilities to this critical catalog, highlighting the ongoing need for proactive cybersecurity measures.

Understanding the KEV Catalog

The KEV Catalog serves as a prioritized list of cybersecurity weaknesses that pose meaningful risks to organizations. These vulnerabilities are frequently targeted in cyberattacks, making their timely remediation crucial. By identifying and addressing these flaws,organizations can dramatically reduce their exposure to attacks and protect their sensitive data and systems. CISA maintains this catalog to provide a focused resource for cybersecurity professionals and to drive rapid patching of critical weaknesses.

Recent Additions and associated Risks

The addition of two new vulnerabilities to the KEV Catalog underscores the dynamic nature of the threat landscape. These vulnerabilities represent active attack vectors,meaning malicious cyber actors are already exploiting them. While specific details of the added vulnerabilities are constantly evolving, their presence in the KEV Catalog confirms their potential for significant impact.They present significant risks to not only federal enterprise, but any institution vulnerable to exploitation. [[2]] provides alerts regarding these vulnerabilities.

Who Needs to Take Action?

While Binding Operational Directive (BOD) 22-01 specifically applies to Federal Civilian Executive Branch (FCEB) agencies, CISA [[1]] strongly recommends that all organizations prioritize remediation of KEV Catalog vulnerabilities. This includes private sector companies, critical infrastructure operators, educational institutions, and individuals. Proactive vulnerability management is a fundamental practice for mitigating cyber risk.

Key Steps for Remediation

  • Identify Affected Systems: determine if your organization uses any software or systems impacted by the newly added vulnerabilities.
  • Prioritize Patching: Apply security updates and patches as quickly as possible, prioritizing those identified in the KEV Catalog.
  • Implement Workarounds: If immediate patching is not feasible, implement temporary workarounds to reduce your exposure.
  • Continuous Monitoring: Regularly monitor your systems for signs of compromise, and stay informed about emerging threats.

Investing in Cybersecurity Training

Effective vulnerability management relies on a skilled cybersecurity workforce. CISA offers a range of [[3]] cybersecurity training and exercises designed to enhance the capabilities of federal employees, private sector professionals, and the general public. Building a cyber-ready workforce is essential for defending against the ever-evolving threat landscape.

Looking Ahead

CISA will continue to update the KEV Catalog as new vulnerabilities are discovered and exploited. Staying informed about these updates and proactively addressing identified weaknesses is crucial for maintaining a strong cybersecurity posture. By working together, we can build a more secure and resilient digital infrastructure for all.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”