CISA BOD 22-01 iOS KEV patch order
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered Federal Civilian Executive Branch agencies to secure affected iOS devices by March 26 after adding three Coruna vulnerabilities to its Known Exploited Vulnerabilities catalog. The directive matters because the flaws were linked to cyberespionage and crypto-theft activity, raising immediate federal remediation pressure. CISA also urged all organizations to patch the issues or stop using the product if fixes are unavailable.
Related Happenings
CISA revises CIRCIA town hall schedule
Public Sector Action
First: 26.05.2026 15:00
Last: 26.05.2026 15:00
Sources 1
About this happening:
CISA **revised the schedule** for **virtual town halls** on the **CIRCIA rulemaking**, reopening stakeholder engagement on a cybersecurity reporting rule that will affect **critic...
CISA revises CIRCIA town hall schedule
Public Sector ActionAbout this happening: CISA **revised the schedule** for **virtual town halls** on the **CIRCIA rulemaking**, reopening stakeholder engagement on a cybersecurity reporting rule that will affect **critic...
CISA orders FCEB patching for CVE-2026-9082
Public Sector Action
First: 26.05.2026 11:46
Last: 26.05.2026 11:46
Sources 1
About this happening:
**CISA** added **CVE-2026-9082** to the **KEV Catalog** and ordered **FCEB agencies** to patch **Drupal** by **May 27**, turning an actively exploited flaw into a mandatory federa...
CISA orders FCEB patching for CVE-2026-9082
Public Sector ActionAbout this happening: **CISA** added **CVE-2026-9082** to the **KEV Catalog** and ordered **FCEB agencies** to patch **Drupal** by **May 27**, turning an actively exploited flaw into a mandatory federa...
Congress demands CISA answers on GitHub credential leak
Public Sector Action
First: 22.05.2026 19:34
Last: 22.05.2026 19:34
Sources 1
About this happening:
**Lawmakers in both houses of Congress** demanded answers from **CISA** after a contractor exposed **AWS GovCloud keys** and other secrets on **public GitHub**. The letters presse...
Congress demands CISA answers on GitHub credential leak
Public Sector ActionAbout this happening: **Lawmakers in both houses of Congress** demanded answers from **CISA** after a contractor exposed **AWS GovCloud keys** and other secrets on **public GitHub**. The letters presse...
CISA launches KEV Nomination Form
Public Sector Action
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a **new Nomination Form** for the **KEV catalog**, giving **researchers, vendors, and industry partners** a direct way to report **known exploited vulnerabilities**....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a **new Nomination Form** for the **KEV catalog**, giving **researchers, vendors, and industry partners** a direct way to report **known exploited vulnerabilities**....
CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Public Sector Action
First: 15.05.2026 08:28
Last: 15.05.2026 08:28
Sources 1
About this happening:
**CISA** added **CVE-2026-20182** to the **KEV catalog** and ordered **Federal Civilian Executive Branch agencies** to remediate **Cisco Catalyst SD-WAN Controller** by **May 17,...
CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Public Sector ActionAbout this happening: **CISA** added **CVE-2026-20182** to the **KEV catalog** and ordered **Federal Civilian Executive Branch agencies** to remediate **Cisco Catalyst SD-WAN Controller** by **May 17,...
Timeline
-
06.03.2026 17:57 2 articles · 2mo ago
CISA adds three Coruna iOS flaws to KEV and orders federal patching
Legal Policy Action UpdateCISA added three of the 23 Coruna iOS vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected devices by March 26 under Binding Operational Directive (BOD) 22-01. The directive followed reporting that the flaws were exploited in spyware and crypto-theft attacks using the Coruna exploit kit, and CISA urged all organizations to apply vendor mitigations or discontinue use if fixes are unavailable.
Show sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43