HomeSecurityCISA adds 7 vulnerabilities to the KEV List

CISA adds 7 vulnerabilities to the KEV List

The Cybersecurity and Infrastructure Security Agency, known as CISA, has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) list, following indications that they are already being actively used in real-world cyberattacks. This move is considered particularly important for organizations and system administrators, as the inclusion of a vulnerability in the KEV list means that there are exploits available or confirmed attacks that exploit these security gaps.

CISA

The new additions include both older and more modern vulnerabilities affecting Microsoft and Adobe, with several of them related to buffer overflow, use-after-free flaws and privilege escalation techniques. According to CISA, such weaknesses have long been key tools for cybercriminal groups.

See also: Pardus Linux: Chain of vulnerabilities allows complete system takeover

The vulnerabilities that came under the CISA microscope

Among the CVEs added to the KEV list are the Windows buffer overflow vulnerability , CVE - 2008-4250 , and the DirectX byte overwrite vulnerability CVE-2009-1537 , , two vulnerabilities that continue to be exploited even years after their initial disclosure. This fact shows that many organizations are still using outdated or legacy systems that remain exposed to known attacks.

The list also includes critical use-after-free vulnerabilities in Microsoft Internet Explorer, specifically CVE-2010-0249, CVE-2010-0806. Although Internet Explorer has been retired by Microsoft for years, many enterprises still maintain old compatibility environments, which significantly increases the risk of attacks.

At the same time, serious vulnerabilities were also identified in Microsoft Defender, such as CVE-2026-41091 related to privilege escalation, as well as a Denial of Service vulnerability (CVE-2026-45498). Exploiting such flaws could allow attackers to gain elevated privileges within a system or disable key security features.

Finally, CISA added CVE-2009-3459, a Heap-Based Buffer Overflow in Adobe Acrobat and Reader.

See also: Drupal Core vulnerability allows RCE attacks on PostgreSQL sites

CISA adds 7 vulnerabilities to the KEV List

What is the KEV list and why is it considered so important?

The KEV list was created under BOD 22-01, which was designed to mitigate the risk of known and actively exploited vulnerabilities in United States federal networks. The list serves as a dynamic repository of CVEs that are considered high priority due to actual exploitation by cybercriminals.

The directive requires Federal Civilian Executive Branch agencies to fix specific vulnerabilities within a specified timeframe. The goal is to reduce the attack surface before threats spread to critical infrastructure or government networks.

Although BOD 22-01 applies primarily to federal agencies, CISA notes that the KEV list should be treated as a critical security tool by private businesses, service providers, and organizations of all sizes.

Old vulnerabilities remain an active risk

One of the most concerning aspects of the new announcement is that several of the vulnerabilities added to the list are old. This reveals a perennial problem in cybersecurity: the inability of many organizations to retire legacy software or apply security patches in a timely manner.

Attackers continue to exploit known vulnerabilities because they know that a large percentage of corporate infrastructure remains unprotected. Old browsers, outdated operating systems, and outdated applications continue to be key entry points for ransomware attacks, data breaches , and privilege escalation exploits.

See also: YellowKey BitLocker bypass – Microsoft's mitigations and what IT admins should change

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Buffer overflow and use-after-free vulnerabilities in particular are considered particularly dangerous, as they can lead to remote code execution, complete system control, or malware installation without user interaction.

CISA adds 7 vulnerabilities to the KEV List

CISA calls on organizations to act immediately

The US cybersecurity agency is urging all organizations to prioritize fixing vulnerabilities on the KEV list. According to CISA, timely patching and proper vulnerability management remain among the most effective defenses against modern cyberattacks.

The agency also emphasizes that the KEV list will continue to be dynamically updated with new vulnerabilities that meet the criteria for active exploitation. This means that security administrators should systematically monitor CISA updates and promptly adjust their security policies.

In an era where cyberattacks are becoming increasingly automated and aggressive, the existence of unpatched systems remains one of the greatest risks for public and private organizations worldwide.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS