type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
CISA Adds Two Known Exploited Vulnerabilities to KEV Catalogue
Summary
CISA added two newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-07-27, continuing the steady cadence of KEV updates that signal active exploitation in the wild.
Key Details
| Field | Detail |
|---|---|
| Organisation | Cybersecurity and Infrastructure Security Agency (CISA) |
| Date | 2026-07-27 |
| Vulnerabilities added | 2 |
| Catalogue | Known Exploited Vulnerabilities (KEV) |
Significance
KEV additions carry Binding Operational Directive (BOD) 22-01 implications for US federal civilian executive branch agencies, which must remediate listed vulnerabilities within prescribed timelines. The KEV catalogue also serves as a prioritisation signal for the broader security community.