BOD 26-04
4 published articles
Known Exploited Vulnerabilities
Active exploits push Progress LoadMaster flaw onto CISA's must-patch list
CISA's KEV catalog now includes CVE-2026-8037, an actively exploited command injection flaw in Progress LoadMaster. Under BOD 26-04, the entry turns a one-line advisory into a federal patch priority, and CISA urges every organization to treat the list the same way.
2026-08-10
CISA
CISA adds two actively exploited flaws to its must-patch catalog
CISA added CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog, requiring rapid remediation for federal agencies. The advisory definitions behind these listings clarify how industrial control and medical device vulnerabilities are disclosed and mitigated.
2026-08-02
CISA KEV
Cisco flaw on CISA's KEV list: patching is not enough anymore
CISA adds a Cisco firewall password flaw to its KEV catalog. Under BOD 26-04, federal agencies must now investigate for pre-patch exploitation, not just apply the patch. The same expectation applies to recent Check Point and Microsoft SharePoint vulnerabilities.
2026-08-02
Cybersecurity
Two new CISA alerts, one hard question: did they get in before you patched?
CISA adds CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog. Under BOD 26-04, agencies must now check for pre-patch compromises and prioritize by risk, making breach detection just as critical as patching speed.
2026-07-25