#KEV
This archive brings together analysis and updates on vulnerabilities known to be actively exploited, with attention to what that means for organizations across Latin America. Readers will find context on patch prioritization, operational risk, and defensive decisions around flaws that often move quickly from technical notice to real exposure.
CISA Adds Four Critical CVEs to KEV Catalog
CISA added four actively exploited flaws in Apple, Microsoft and VMware to its KEV catalog and set the federal deadline for Aug. 21.
Aug 22, 2026 · 3 min
CISA adds CVE-2026-34486 to KEV catalog
CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min
CVE-2026-8037 lands in CISA's KEV catalog
CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
Aug 10, 2026 · 2 min
CISA Adds Cisco FMC CVE-2026-20316 to KEV
CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
Jul 30, 2026 · 2 min
CISA adds CVE-2026-16812 to KEV catalog
CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
Jul 28, 2026 · 2 min
CVE-2026-56291 hits Balbooa Forms on Joomla
Balbooa Forms for Joomla had a critical RCE abused as a zero-day. Patch 2.4.1 landed July 9, and CISA added it to KEV.
Jul 15, 2026 · 3 min