CISA adds Hikvision and Rockwell Automation flaws to KEV catalog
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2017-7921 and CVE-2021-22681 to the Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation and pushing FCEB agencies to prioritize remediation by March 26, 2026.
Related Happenings
CISA BOD 26-04 remediation requirements
Advisory/Mitigation
H score31
First: 11.06.2026 15:46
Last: 11.06.2026 15:46
Sources 1
About this happening:
CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...
CISA BOD 26-04 remediation requirements
Advisory/MitigationAbout this happening: CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector Action
H score50
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
About this happening:
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector ActionAbout this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/Mitigation
H score32
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
CISA and authoring agencies issued April 7 mitigation guidance for internet-facing OT assets, warning that US critical infrastructure operators using Rockwell Au...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/MitigationAbout this happening: CISA and authoring agencies issued April 7 mitigation guidance for internet-facing OT assets, warning that US critical infrastructure operators using Rockwell Au...
CISA BOD 22-01 order for FCEB iOS patching
Public Sector Action
H score38
First: 23.03.2026 10:37
Last: 23.03.2026 10:37
Sources 1
About this happening:
CISA ordered FCEB agencies to secure devices against DarkSword-linked iOS flaws, tightening federal exposure to attacks that enabled sandbox escape and remote co...
CISA BOD 22-01 order for FCEB iOS patching
Public Sector ActionAbout this happening: CISA ordered FCEB agencies to secure devices against DarkSword-linked iOS flaws, tightening federal exposure to attacks that enabled sandbox escape and remote co...
Timeline
-
06.03.2026 08:30 2 articles · 4mo ago
CISA adds Hikvision and Rockwell flaws to KEV catalog
Initial DisclosureCISA added CVE-2017-7921, an improper authentication flaw affecting multiple Hikvision products, and CVE-2021-22681, an insufficiently protected credentials flaw affecting Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers, to its Known Exploited Vulnerabilities (KEV) catalog after citing active exploitation. The addition followed SANS Internet Storm Center detection of exploit attempts against Hikvision cameras susceptible to CVE-2017-7921, while no public report described attacks involving CVE-2021-22681.
Show sources
- Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog — thehackernews.com — 06.03.2026 08:30
- Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog — thehackernews.com — 06.03.2026 08:30
-
06.03.2026 08:30 1 articles · 4mo ago
FCEB remediation deadline set for March 26, 2026
Legal Policy Action UpdateFederal Civilian Executive Branch agencies are recommended to update to the latest supported software versions for affected Hikvision and Rockwell Automation products by March 26, 2026 under Binding Operational Directive (BOD) 22-01. CISA also urges other organizations to prioritize timely remediation of KEV Catalog vulnerabilities as part of vulnerability management practice.
Show sources
- Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog — thehackernews.com — 06.03.2026 08:30