CISA adds four exploited vulnerabilities to its KEV catalog

CISA adds 4 new exploited vulnerabilities to its KEV catalog: SonicWall SMA1000 and Microsoft AD FS and SharePoint. Update your systems to prevent attacks.

miércoles, 15 de julio de 2026 • 5 min read • Q2BSTUDIO Team

CISA updates its list of actively exploited vulnerabilities

The recent update of the Catalog of Known Exploited Vulnerabilities (KEV) by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has once again put the spotlight on the importance of risk-based vulnerability management. This time, four security flaws have been incorporated that are already being actively exploited by malicious actors: two in SonicWall SMA1000 appliances (a Server-Side Request Forgery vulnerability and a code injection vulnerability), and two in Microsoft products – Active Directory Federation Services (ADFS) and SharePoint Server – that allow access controls to be circumvented or critical functions to be executed without authentication. Although BOD 26-04 is mandatory only for federal civil executive branch (FCEB) agencies, CISA urges all organizations, public and private, to adopt a similar approach of prioritization based on actual risk.

The inclusion of these four vulnerabilities in the KEV catalog is not an isolated event. It follows a well-known pattern: cybercriminals exploit flaws with public proofs of concept, often before patches are available or properly applied. In the case of SonicWall vulnerabilities, both affect SMA1000 appliances, used to provide secure remote access to corporate networks. Server-side request forgery (SSRF) allows an attacker to send requests through the device to internal resources, while code injection grants the ability to execute arbitrary commands. Together, they can fully compromise the appliance and from there pivot to the internal network. Microsoft, for its part, has confirmed that vulnerabilities in ADFS and SharePoint are being actively exploited, raising the urgency of applying the corresponding security updates.

BOD directive 26-04, issued in November 2024, introduces a significant change to how federal agencies must approach security updates. It is no longer just a matter of patching everything that appears, but of prioritizing according to risk. Vulnerabilities in the KEV catalogue that affect publicly exposed assets and which, after exploitation, give full control of the system must be corrected within a very short period of time (usually two weeks). In addition, it forces agencies to verify if the system was compromised before applying the patch. This approach based on threat intelligence is replicable in the private sector and increasingly recommended by cybersecurity consultancies, such as those offered by Q2BSTUDIO.

Q2BSTUDIO, as a software and technology development company, understands that cybersecurity is not an optional add-on, but a transversal pillar in any digital project. Our cybersecurity and pentesting services are designed to help organizations identify, prioritize, and remediate vulnerabilities efficiently, integrating practices such as dynamic risk analysis and continuous monitoring. Just as CISA pushes the use of the KEV catalog as a reference, we work with our clients to align their security policies with international best practices, including automating patching processes and conducting regular penetration testing.

One of the key lessons from this new wave of vulnerabilities is the need for tailored applications that incorporate security controls by design. When an organization develops custom software, it has the opportunity to implement input validations, secure session management, and architectures that mitigate attacks such as code injections or SSRFs. At Q2BSTUDIO, we combine our development expertise with a default security approach, offering solutions that not only meet functional requirements, but also withstand the most current threats. In addition, our capabilities in AWS and Azure cloud services allow us to deploy scalable environments with optimized security configurations, reducing the attack surface.

The current landscape also calls for a change in business mindset: cybersecurity must be understood as an ongoing process, not a one-off project. Vulnerabilities like the ones CISA just added show that attackers don't rest and that legacy systems, without proper patch management, are easy targets. As a result, more and more companies are turning to artificial intelligence services to automate anomaly detection and incident response. AI agents can analyze millions of security events in real-time, prioritize alerts, and suggest corrective actions, freeing up human teams for more strategic tasks. At Q2BSTUDIO, we integrate enterprise AI into our cybersecurity solutions, facilitating proactive and adaptive defense.

We cannot ignore the role of business intelligence in this context. Decisions about patch prioritization and security resource allocation should be based on objective data. The business intelligence services we offer, based on tools such as Power BI, allow you to visualize the status of vulnerabilities in the organization, the level of exposure and the progress of remediations. A well-designed dashboard can show, for example, which assets are publicly exposed and which correspond to vulnerabilities in the KEV catalog, facilitating decision-making aligned with directives such as BOD 26-04.

The inclusion of these four vulnerabilities in the KEV catalog also highlights the importance of having a coordinated disclosure program (CVD). CISA invites any person or organization to report exploited vulnerabilities that are not listed in the catalog, as long as they have a CVE identifier, evidence of exploitation, and clear mitigation guidance. This collaboration mechanism is essential to keep collective knowledge about active threats up to date. At Q2BSTUDIO, we support this philosophy of transparency and collaboration, participating in security communities and helping our clients establish internal vulnerability reporting processes.

For companies that have not yet adopted a risk-based vulnerability management model, this CISA announcement should serve as an urgent reminder. It's not just about complying with regulations, it's about protecting critical assets and business continuity. Organizations that integrate cybersecurity into their digital DNA, from the design phase to operation, are better prepared to deal with incidents. Our team in Q2BSTUDIO combines knowledge of development, cloud, artificial intelligence and data analysis to offer comprehensive support on this path.

All in all, the addition of these four vulnerabilities to the KEV catalog is a wake-up call for the entire industry. Cybersecurity is not a cost, it is an investment. The ability to react quickly to new threats, prioritize based on risk, and maintain an up-to-date security posture makes the difference between falling victim to an attack or being prepared to repel it. From Q2BSTUDIO, we invite organizations to review their security strategies and consider how our cybersecurity solutions, custom software development, and cloud services can help them navigate this complex environment with confidence.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.