#KEV
This archive brings together analysis and updates on vulnerabilities known to be actively exploited, with attention to what that means for organizations across Latin America. Readers will find context on patch prioritization, operational risk, and defensive decisions around flaws that often move quickly from technical notice to real exposure.
Cisco fixes CVE-2026-76504 in SD-WAN Manager
Cisco fixed CVE-2026-76504 in Catalyst SD-WAN Manager, an actively exploited authentication bypass with no workaround.
Oct 1, 2026 · 2 min
CISA Adds CVE-2026-88772 in Citrix NetScaler
CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC
Sep 30, 2026 · 2 min
CISA adds SharePoint CVE-2026-65660 to KEV
CISA added CVE-2026-65660 to the KEV catalog after active exploitation was reported. Microsoft has already released patches.
Sep 27, 2026 · 2 min
CISA adds 7 critical flaws to KEV
CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.
Sep 12, 2026 · 3 min
CISA adds active PaperCut flaws to KEV
CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut
Sep 6, 2026 · 2 min
CISA Adds Citrix, SQL Server CVEs to KEV
CISA added exploited flaws in August, including Citrix NetScaler, Microsoft SQL Server and VMware vCenter, to its KEV catalog.
Aug 29, 2026 · 3 min
CISA adds five critical CVEs to KEV catalog
CISA added CVE-2026-73570 in Zimbra to KEV and set the federal remediation deadline for Aug. 24.
Aug 22, 2026 · 4 min
CISA adds CVE-2026-34486 to KEV catalog
CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min
CVE-2026-8037 lands in CISA's KEV catalog
CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
Aug 10, 2026 · 2 min
CISA Adds Cisco FMC CVE-2026-20316 to KEV
CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
Jul 30, 2026 · 2 min
CISA adds CVE-2026-16812 to KEV catalog
CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
Jul 28, 2026 · 2 min
CVE-2026-56291 hits Balbooa Forms on Joomla
Balbooa Forms for Joomla had a critical RCE abused as a zero-day. Patch 2.4.1 landed July 9, and CISA added it to KEV.
Jul 15, 2026 · 3 min