惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
GbyAI
GbyAI
S
SegmentFault 最新的问题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Visual Studio Blog
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
雷峰网
雷峰网
爱范儿
爱范儿
Vercel News
Vercel News
人人都是产品经理
人人都是产品经理
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
P
Proofpoint News Feed
A
About on SuperTechFans
I
InfoQ
F
Fortinet All Blogs
L
LangChain Blog
T
Tailwind CSS Blog

Cybersecurity and Infrastructure Security Agency CISA

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats | CISA China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies | CISA CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models with Industrial-Scale Knowledge Distillation Campaigns to Shortcut AI Development | CISA Critical Manufacturing Sector Profile | CISA Commercial Facilities Sector Profile | CISA CareCam Pro IP Cameras | CISA CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA Vulnerability Summary for the Week of August 31, 2026 | CISA CISA Adds One Known Exploited Vulnerability to Catalog | CISA Tycon Systems TPDIN-Monitor-WEB3 | CISA Pyramid Solutions NetStaX EtherNet/IP Stack | CISA Inductive Automation Ignition | CISA Rockwell Automation 1756-ENBT Module | CISA Rockwell Automation ArmorStart LT | CISA Rockwell Automation ControlFLASH | CISA IXON VPN Client | CISA OPCFoundation OPC UA LocalDiscoveryServer (LDS) | CISA CISA Adds Seven Known Exploited Vulnerabilities to Catalog | CISA Rockwell Automation Historian ME | CISA Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix | CISA Rockwell Automation FactoryTalk Activation Manager | CISA Rockwell Automation Logix Platform | CISA Rockwell Automation Redundancy Module Configuration Tool | CISA Rockwell Automation RSLinx Classic | CISA From Awareness to Action: Insider Threat Mitigation in an Evolving Security Environment | CISA CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA Vulnerability Summary for the Week of August 24, 2026 | CISA All-Line Equipment Company Fuel-Boss | CISA Ebyte NA111-M | CISA Applied Systems Engineering ASE2000 V2 Communications Test Set | CISA
CISA Adds Three Known Exploited Vulnerabilities to Catalo...
chayes · 2026-08-28 · via Cybersecurity and Infrastructure Security Agency CISA

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2023-49105 ownCloud Improper Authentication Vulnerability
  • CVE-2026-53362 Linux Kernel Unspecified Vulnerability
  • CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability 

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.