CISA Adds Eight Actively Exploited Flaws to KEV, Orders Federal Patching by April–May 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) notified the public that it has expanded its Known Exploited Vulnerabilities (KEV) catalog with eight additional flaws. Among the newly listed issues are three vulnerabilities that affect Cisco Catalyst SD-WAN Manager; CISA cited evidence these weaknesses are being abused in the wild.
Below are the newly added entries and their details:
- CVE-2023-27351 (CVSS: 8.2) – An authentication bypass in PaperCut NG/MF via the SecurityRequestFilter class that can allow attackers to circumvent login controls on vulnerable deployments.
- CVE-2024-27199 (CVSS: 7.3) – A relative path traversal flaw in JetBrains TeamCity that could be leveraged to carry out limited administrative actions.
- CVE-2025-2749 (CVSS: 7.2) – A path traversal issue in Kentico Xperience that may permit an authenticated Staging Sync Server to place arbitrary data at path-relative locations.
- CVE-2025-32975 (CVSS: 10.0) – An improper authentication vulnerability in Quest KACE Systems Management Appliance (SMA) that can let an attacker impersonate legitimate users without valid credentials.
- CVE-2025-48700 (CVSS: 6.1) – A cross-site scripting (XSS) flaw in Synacor Zimbra Collaboration Suite (ZCS) that could enable execution of arbitrary JavaScript in a user session and lead to unauthorized access to sensitive information.
- CVE-2026-20122 (CVSS: 5.4) – In Cisco Catalyst SD-WAN Manager, incorrect use of privileged APIs can allow an attacker to upload and overwrite files arbitrarily and elevate to vManage user privileges.
- CVE-2026-20128 (CVSS: 7.5) – Also in Cisco Catalyst SD-WAN Manager, passwords stored in a recoverable form could enable a local authenticated but low-privileged user to access a credential file and obtain DCA user privileges.
- CVE-2026-20133 (CVSS: 6.5) – A sensitive information exposure in Cisco Catalyst SD-WAN Manager that can allow remote attackers to view confidential data on affected systems.
Because of the active exploitation evidence, CISA set remediation timelines for Federal Civilian Executive Branch (FCEB) agencies: the three Cisco Catalyst SD-WAN Manager issues should be addressed by April 23, 2026, while the remaining vulnerabilities must be mitigated by May 4, 2026.