Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV directive for CVE-2026-20133

Public Sector Action
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directive matters because CISA said the flaw was being used in active exploitation against Cisco Catalyst SD-WAN Manager. CISA also pointed agencies to Emergency Directive 26-03 and related hardening guidance if mitigations were needed.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score46 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

CISA-led joint advisory on Russian router targeting

Public Sector Action
H score32 First: 14.07.2026 15:00 Last: 14.07.2026 15:00 Sources 1

About this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...

Pentagon suspends CMMC phase two for 60-day review

Public Sector Action
H score24 First: 14.07.2026 09:37 Last: 14.07.2026 09:37 Sources 1

About this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...

Timeline

  1. 21.04.2026 15:30 2 articles · 2mo ago

    CISA KEV directive for CVE-2026-20133

    Initial Disclosure

    CISA moved CVE-2026-20133 into the KEV Catalog and set a Friday, April 24 deadline for FCEB agencies to secure their networks. The order was issued after CISA cited evidence of active exploitation.

    Show sources