Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV remediation deadlines for exploited CVEs

Public Sector Action
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Agencies must apply updates or mitigations or discontinue use, turning the notice into an immediate operational requirement. CISA also set a September 28 deadline for CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS.

Related Happenings

CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw

Public Sector Action
H score36 First: 16.06.2026 13:47 Last: 16.06.2026 13:47 Sources 1

About this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...

CISA BOD 26-04 remediation requirements

Advisory/Mitigation
H score31 First: 11.06.2026 15:46 Last: 11.06.2026 15:46 Sources 1

About this happening: CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...

CERT-In 12-hour KEV remediation guidance

Advisory/Mitigation
H score39 First: 26.05.2026 13:30 Last: 26.05.2026 13:30 Sources 1

About this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...

CISA launches KEV Nomination Form

Public Sector Action
H score38 First: 21.05.2026 15:00 Last: 21.05.2026 15:00 Sources 1

About this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....

Timeline

  1. 25.09.2026 20:24 2 articles · 1h ago

    CISA adds WSO2 and Adobe Commerce flaws to KEV and orders September 27 remediation

    Legal Policy Action Update

    CISA added CVE-2026-5430 in multiple WSO2 products and CVE-2026-71362 in Adobe Commerce to the Known Exploited Vulnerabilities catalog after warning that hackers are exploiting both flaws. Federal agencies using the affected products must apply recommended updates or mitigations, or discontinue use, by Sunday, September 27.

    Show sources
  2. 25.09.2026 20:24 1 articles · 1h ago

    CISA gives SharePoint and RouterOS flaws a September 28 federal remediation deadline

    Legal Policy Action Update

    CISA also directed federal agencies to fix CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS by Monday, September 28. The notice extends the remediation requirement to the additional exploited flaws beyond the two critical KEV entries.

    Show sources