<p>CISA has added seven new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2008-4250" target="_blank">CVE-2008-4250</a> Microsoft Windows Buffer Overflow Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2009-1537" target="_blank">CVE-2009-1537</a> Microsoft DirectX NULL Byte Overwrite Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2009-3459" target="_blank">CVE-2009-3459</a> Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2010-0249" target="_blank">CVE-2010-0249</a> Microsoft Internet Explorer Use-After-Free Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2010-0806" target="_blank">CVE-2010-0806</a> Microsoft Internet Explorer Use-After-Free Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-41091" target="_blank">CVE-2026-41091</a> Microsoft Defender Elevation of Privilege Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-45498" target="_blank">CVE-2026-45498</a> Microsoft Defender Denial of Service Vulnerability</li> </ul> <p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.</p> <p><a href="https://www.cisa.gov/binding-operational-directive-22-01">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href="https:
CRITICAL
vulnerabilities
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CyberHawk Threat Intel — IOC Scanner, Live IOC Feed (3.6M+ indicators), Infostealer Intelligence, Threat Map, MISP Feeds, GitHub Arsenal, Courses and more. Free to join.
Register Free →
Source Attribution
This intelligence summary is sourced from US-CERT Alerts and curated by CyberHawk Threat Intel for the security community. Read the complete article at the source link.
Read original at US-CERT Alerts →
This intelligence summary is sourced from US-CERT Alerts and curated by CyberHawk Threat Intel for the security community. Read the complete article at the source link.
Read original at US-CERT Alerts →
Accelerate Your Security Operations
CyberHawk Threat Intel is a complete Cyber Intelligence Platform — one place for every tool a security professional needs. Built by Rudra Verma, Senior Security Architect and Researcher, CyberHawk Consultancy.
IOC Scanner — scan any domain, IP, hash, URL
Live IOC Feed — 3.6M+ indicators, filterable
Infostealer Intelligence — live compromised creds
Live Threat Map — real-time global attack vectors
MISP Threat Feeds — CIRCL, Feodo, Botvrij, more
GitHub Arsenal — curated security tools and scripts
Security Blog — CVE advisories and threat research
Video Courses — cybersecurity training and education
SOPs and Playbooks — SecOps procedures
Analyst Library — references and toolkits
Scan Reports — historical threat intelligence
Cyber News — this feed, aggregated in-platform