Menu Close

CISA KEV Catalog Adds Pressure On Agencies

CISA KEV Catalog dashboard reviewed by a federal cybersecurity analyst

CISA KEV Catalog additions have become a more time-sensitive signal for federal cyber teams. As of the August 11, 2026 catalog version, the list contained 1,665 vulnerabilities across 276 vendors, and 181 CVEs had been added in 2026 through that date, a 16.8% increase over the same period in 2025, according to KEV catalog statistics. Those figures do not mean every listed flaw has the same operational risk, but they show why federal agencies are being pushed to rank remediation by exploitation evidence rather than by CVSS score alone.

Why CISA KEV Catalog Changes Matter

What The CISA KEV Catalog Measures

The CISA KEV Catalog is a list of vulnerabilities that have evidence of active exploitation. That makes it different from a broad vulnerability database. The National Vulnerability Database held 376,310 CVE records as of mid-August 2026, while the KEV list represented about 0.44% of those records. The smaller share matters: the catalog is not a count of all serious flaws, but a filtered set where known exploitation has already shifted the risk calculation.

That distinction helps explain why agencies cannot treat the list as a normal patch queue. A vulnerability may have a lower theoretical score than another issue but still deserve faster action if attackers have already used it. The research also showed that about 60.8% of 2026 KEV additions had CVE identifiers assigned in 2026. That suggests many flaws were being cataloged in the same year they were named, reducing the time available for slow inventory checks and long maintenance windows.

Why The Three-Day Clock Changes Operations

Under BOD 26-04, federal civilian executive branch agencies were directed to prioritize rapid remediation for KEV entries, with emphasis on flaws affecting publicly exposed assets and vulnerabilities that allow total control after exploitation. Since March 2026, 49.3% of new entries had received a three-day remediation deadline instead of the older flat 21-day requirement. A three-day window changes the practical workload for asset owners, security operations centers, and change advisory boards.

The shorter clock does not remove the need for testing. It does reduce tolerance for unclear ownership, incomplete asset records, and delayed approvals. Agencies need to know whether affected software is internet-facing, whether compensating controls exist, and whether evidence of compromise is present before a patch is applied. For related insights on network and security operations management from a trusted source, Camp Tech Wise offers articles on technology topics that can guide non-specialist stakeholders in understanding infrastructure dependencies.

Recent Additions Show Asset Exposure Risk

September 2, 2026 Additions

On September 2, 2026, CISA added seven vulnerabilities to the catalog, including issues affecting Sangoma Switchvox, BerriAI LiteLLM, JFrog Artifactory, and multiple SonicWall SMA1000 entries, according to the mirrored CISA alert. The flaw categories cited in the research included SQL injection, improper authentication, and issues in remote access or development infrastructure products.

Those product types are operationally significant because they often sit close to identity, remote connectivity, software delivery, or administrative workflows. A remote access appliance can expose internal services if it is compromised. An artifact repository can affect software build and deployment paths. An authentication weakness in an AI service component can create access-control risk if the product is reachable by untrusted users. The available research does not provide exploit chains or agency impact counts for those entries, so the defensible interpretation is narrower: these additions identify active exploitation concerns, not a complete measurement of compromise prevalence.

July And August 2026 Additions

Earlier 2026 additions followed the same pattern of enterprise infrastructure exposure. On August 18, 2026, four vulnerabilities were added, including issues in Microsoft IKE Service Extensions, SharePoint weak authentication, VMware vCenter path traversal, and Apple macOS improper authentication. On July 14, 2026, CISA added four more, including SonicWall SMA1000 server-side request forgery and code injection issues, plus Microsoft Active Directory Federation Services and SharePoint missing-authentication functionality. On July 16, 2026, three entries were added, covering two Fortinet FortiSandbox command injection issues and a SharePoint deserialization vulnerability.

The repeated appearance of remote access, identity, virtualization, collaboration, and security tooling supports a practical remediation rule: agencies should map KEV entries to business-critical infrastructure first, not just endpoint counts. A single vulnerable identity or remote access system may create more operational exposure than many isolated workstations. A related analysis of how active exploitation should reset patch queues is available in KEV vulnerability prioritization.

How Agencies Should Prioritize Remediation

Security team reviewing remediation tasks during an operations meeting

Public Exposure And Control Risk

The CISA KEV Catalog should be read as a prioritization aid, not as a replacement for local risk assessment. Agencies still need to confirm whether the affected product exists in their environment, whether it is reachable from the public internet, whether the vulnerable function is enabled, and whether the asset supports critical services. BOD 26-04’s focus on publicly exposed assets and post-exploitation control aligns with that approach.

A practical order of work starts with asset confirmation and exposure review. Internet-facing appliances, identity services, VPN or remote access systems, collaboration platforms, and administrative consoles should be checked first when they match a KEV entry. Internal-only systems still require remediation, but their urgency may depend on segmentation, privilege boundaries, and signs that attackers have already reached adjacent systems.

  • Confirm whether the vulnerable product and version are present in the agency environment.
  • Identify whether the affected service is publicly exposed or reachable through trusted partner links.
  • Check for signs of compromise before applying fixes, as required by the updated directive expectations.
  • Apply vendor remediation or mitigation within the assigned deadline, prioritizing three-day entries first.
  • Validate that the fix was applied and that no affected asset remains outside the tracking process.

Evidence Before And After Patching

Checking for compromise before patching is a key operational change because patching alone may not remove attacker access if credentials, tokens, web shells, or configuration changes were created before the fix. The research notes that the directive established expectations to check for signs of compromise before applying patches, especially for KEV-listed issues. That sequencing affects incident response: teams may need logs, endpoint telemetry, network records, and administrator activity records before systems are restarted or modified.

This requirement also raises cost and staffing questions. Three-day remediation windows can strain teams that manage legacy software, shared service platforms, or systems with limited maintenance periods. Agencies with incomplete asset inventories face higher friction because they must first discover affected products before remediation can start. The data supports prioritizing exploited vulnerabilities, but it does not prove that every agency has the same staffing, tooling, or contractual capacity to meet each deadline without trade-offs.

CISA KEV Catalog Prioritization For Agencies

Limits Of The Current Data

The CISA KEV Catalog provides a strong evidence-based filter, but its limits should stay visible. The count of 1,665 entries as of August 11, 2026 does not measure all vulnerabilities that could harm federal systems. It measures vulnerabilities with known exploitation evidence that met catalog criteria. The 339 entries associated with known ransomware campaigns, about 20.4% of the catalog by that date, identify a major subset of concern, but the research does not provide detail on which agencies were affected or how often each flaw was used.

For federal agencies, the sound policy response is disciplined triage: confirm exposure, search for compromise, remediate within the assigned deadline, and verify closure. The recent additions from July, August, and September 2026 show that attackers continued to focus on software that supports authentication, remote access, collaboration, virtualization, and security administration. The evidence does not support panic, but it does support shorter decision cycles and better asset visibility. Agencies that treat KEV entries as an operational queue, rather than a periodic compliance report, are better aligned with the direction set by BOD 26-04.