Tag

#KEV

22 stories taggedKEV · page 2 of 2.

Policy & Regulation

CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw

CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.

2 min read
Vulnerabilities

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive

BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

2 min read
Vulnerabilities

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List

An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.

2 min read
Policy & Regulation

CISA's New Patching Directive Drops CVSS as the North Star

BOD 26-04 introduces a four-factor framework that prioritizes internet exposure, active exploitation, and attacker automation over raw severity scores — and gives agencies three days to act on the worst cases.

3 min read
Policy & Regulation

CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV

Three vulnerabilities added to the Known Exploited Vulnerabilities catalog activate BOD 22-01 remediation deadlines for civilian agencies.

2 min read
Vulnerabilities

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited

The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

2 min read
Vulnerabilities

CISA's KEV List Just Picked Up Langflow and Apex One — Both Already Being Hit

Two flaws, one AI workflow tool and one veteran endpoint suite, now carry a federal patch deadline because attackers got there first.

2 min read
© 2026 Threat Vectr