San Francisco, CA – The Cybersecurity and Infrastructure Security Agency (CISA) this week added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling an urgent require for patching across a diverse range of software. The list includes flaws in widely used products like Google Chrome and Microsoft Windows, alongside vulnerabilities in collaboration platforms and security software. This action underscores the persistent and evolving threat landscape, where attackers readily exploit both newly discovered vulnerabilities and those that have lingered for years.
The KEV catalog, established under Binding Operational Directive (BOD) 22-01, serves as a prioritized list of cybersecurity risks for federal agencies, mandating remediation within a specified timeframe – in this case, by March 10, 2026. However, CISA strongly encourages all organizations, public and private, to address these vulnerabilities proactively to minimize their exposure to cyberattacks. The inclusion of a vulnerability in the KEV catalog doesn’t necessarily indicate a new threat, but rather confirms active exploitation “in the wild,” making immediate action critical.
Among the most prominent additions is CVE-2026-2441, a zero-day vulnerability affecting the Google Chromium web browser engine. This flaw, classified as a use-after-free condition, allows a remote attacker to potentially execute arbitrary code on a vulnerable system. Google was made aware of the vulnerability on February 11, 2026, by security researcher Shaheen Fazim and swiftly released updates to address the issue. The Stable channel has been updated to version 145.0.7632.75/76 for Windows and Macintosh, and 144.0.7559.75 for Linux. Users are strongly advised to update their browsers immediately to mitigate this risk.
Decades-Old Microsoft Flaw Re-Emerges
Perhaps more concerning is the re-emergence of CVE-2008-0015, a remote code execution vulnerability in the Microsoft Windows Video ActiveX Control dating back to 2008. This flaw, triggered by a stack-based buffer overflow, highlights the dangers of neglecting to patch legacy systems. The fact that this nearly two-decade-old vulnerability is now being actively exploited suggests that attackers are targeting organizations that have either failed to apply previous security updates or are still running outdated and unsupported software. This underscores the importance of maintaining a robust and consistent patching schedule, even for older systems.
ActiveX, a Microsoft technology for creating interactive web content, has been a frequent source of security vulnerabilities over the years. While Microsoft has taken steps to improve the security of ActiveX, its continued presence in many systems makes it a persistent target for attackers. The re-emergence of CVE-2008-0015 serves as a stark reminder that vulnerabilities don’t simply disappear with time; they can be rediscovered and exploited years later.
Broader Range of Vulnerabilities Added to CISA’s List
Beyond Google and Microsoft products, CISA’s updated KEV catalog includes vulnerabilities in several other applications. CVE-2020-7796, a server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite, allows attackers to potentially access sensitive information or perform unauthorized actions on a vulnerable server. SSRF vulnerabilities occur when an application allows an attacker to manipulate the server into making requests to unintended locations.
CVE-2024-7694 affects Team T5 ThreatSonar Anti-Ransomware, a security product designed to protect against ransomware attacks. This vulnerability, stemming from improper file validation, allows an attacker with administrative privileges to upload malicious files, potentially compromising the system it’s intended to protect. This highlights the importance of rigorous security testing even within security products themselves.
CISA added CVE-2026-22769, a hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines, and CVE-2021-22175, another SSRF issue in GitLab. CVE-2026-22769 allows unauthenticated remote access to the operating system, while the GitLab vulnerability, discovered earlier, could allow attackers to access internal resources. These additions demonstrate the breadth of the current threat landscape, impacting a wide range of software and systems.
The Pragmatic Approach of Cybercriminals
Gunter Ollman, CTO at Cobalt, a penetration testing firm, emphasized that the diversity of vulnerabilities in the KEV catalog reflects the pragmatic approach of modern cybercriminals. “They will exploit a brand-new Chrome heap corruption vulnerability just as readily as a 2008-era ActiveX buffer overflow if it gives them reliable access,” Ollman stated. He further noted that the catalog highlights the diverse attack surface organizations must defend, ranging from web browsers and collaboration platforms to endpoint security software. Cobalt provides penetration testing services to help organizations identify and address vulnerabilities before they can be exploited.
Ollman’s assessment underscores the need for continuous, adversary-driven testing. Organizations can’t rely solely on periodic vulnerability scans; they must actively simulate real-world attacks to identify and address weaknesses in their security posture. This includes chaining together exploits, SSRF flaws, and legacy vulnerabilities to understand how attackers might compromise their systems.
The KEV catalog, according to Ollman, is not merely a list of bugs but a “blueprint of what adversaries are successfully monetising today.” This perspective shifts the focus from simply fixing vulnerabilities to understanding how attackers are actively exploiting them and prioritizing remediation efforts accordingly.
What This Means for Organizations and Individuals
The addition of these vulnerabilities to the KEV catalog has significant implications for organizations and individuals alike. Federal agencies are mandated to remediate these flaws by March 10, 2026, but the urgency extends to all users. Proactive patching is the most effective way to mitigate the risk posed by these vulnerabilities.
For individuals, keeping software up to date is crucial. This includes web browsers, operating systems, and any other applications that may be vulnerable. Enabling automatic updates can help ensure that security patches are applied promptly. It’s similarly significant to be cautious about clicking on links or opening attachments from unknown sources, as these could be used to exploit vulnerabilities.
Organizations should prioritize vulnerability management, regularly scanning their systems for known vulnerabilities and applying patches in a timely manner. They should also consider implementing a robust incident response plan to prepare for potential security breaches. Organizations should invest in security awareness training for their employees to help them identify and avoid phishing attacks and other social engineering tactics.
Key Takeaways
- Prioritize Patching: The KEV catalog highlights the critical importance of promptly applying security patches to all software and systems.
- Legacy Systems Pose a Risk: The re-emergence of the 2008 Microsoft vulnerability underscores the dangers of neglecting to patch older systems.
- Diverse Threat Landscape: The vulnerabilities span a wide range of products, demonstrating the need for a comprehensive security approach.
- Continuous Testing is Essential: Organizations should conduct regular penetration testing to identify and address vulnerabilities before they can be exploited.
As CISA continues to update the KEV catalog, organizations and individuals must remain vigilant and proactive in their cybersecurity efforts. The evolving threat landscape demands a continuous commitment to security best practices and a willingness to adapt to new challenges. The next update to the KEV catalog is expected in early April 2026, and organizations should monitor CISA’s website for further information and guidance. Stay informed, stay protected, and share this information with your networks to help improve collective cybersecurity.
Related reading
- Apple Signals September iPhone Event Date and Schedule Clues
- Lost Pokémon Game Resurfaces After 20 Years and Sells for $10,000
- Microsoft Attributes CaptiveCrunch to Russian Threat Actor Midnight Blizzard (archynewsy.com)
- Microsoft Links CaptiveCrunch to Russian Threat Actor Midnight Blizzard (newsdirectory3.com)