Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

CISA adds five actively exploited vulnerabilities to its KEV catalog in March

On March 5, 2026, CISA added five flaws with confirmed in-the-wild exploitation to the catalog that sets binding patch deadlines for federal agencies — and sensible ones for everyone else.

Malik Johnson, · March 23, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
Security analyst reviewing a vulnerability feed on dual monitors

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on March 5, 2026, stating that each has been confirmed to be actively exploited. The catalog is not advisory: under binding operational directives, federal civilian agencies must remediate KEV-listed flaws by set deadlines — generally two to three weeks — and the rest of the security industry treats those dates as the de facto global patch clock. A follow-up addition of one more exploited vulnerability came on March 18, keeping the month's cadence busy.

What is the KEV catalog?

A running list of vulnerabilities CISA has evidence of being exploited in the wild, drawn from vendor advisories, researcher reports, and the agency's own incident work. Since 2021, directives have instructed federal agencies to patch every catalog entry within published timelines. For private organizations, the catalog functions as a free, continuously updated "what attackers are actually using" feed — a short list that cuts through the thousands of CVEs published each year to the dozens that matter.

Which flaws were added in March?

Per CISA's March 5, 2026 announcement, five vulnerabilities across affected products were added based on evidence of active exploitation; the individual entries — CVE identifiers, products, versions, and due dates — are published in the catalog itself. A sixth addition followed on March 18. This report does not enumerate the specific CVEs beyond CISA's announcement, since entry-level detail and any revised due dates belong to the catalog as the source of record.

What should you do now?

  1. Check the catalog against your inventory. Search the KEV catalog for the vendors you run — network equipment, VPNs, file transfer tools, and anything internet-facing come first.
  2. Patch listed items immediately, not on the federal calendar but on your own urgency: actively exploited means someone is trying these flaws against random targets right now.
  3. Subscribe or automate. The catalog ships as JSON, and most vulnerability scanners and patch tools can ingest it directly — configure one of them so future additions reach you without anyone remembering to look.
  4. Use it to prioritize the backlog. If a full patch program feels impossible, the KEV list is the triage order: internet-facing KEV items first, internal KEV items second, everything else after.

The catalog's steady growth — additions arrive most weeks — is the honest state of the internet's maintenance debt. The organizations that fare best are not those with zero vulnerabilities, which do not exist, but those for whom a March 5 addition is a March 6 patch.

Frequently Asked Questions

What is the CISA KEV catalog?
The Known Exploited Vulnerabilities catalog lists flaws CISA has confirmed are being exploited in the wild. Federal agencies must patch entries by directive deadlines, and most of the security industry treats it as the global patch-priority list.
What did CISA add on March 5, 2026?
Five vulnerabilities with confirmed active exploitation, per CISA's announcement, with a sixth added March 18. The CVE-level detail, products, and due dates live in the catalog itself as the source of record.
Does the KEV deadline apply to private companies?
Legally, no — the binding deadlines cover federal civilian agencies. Practically, yes: an actively exploited flaw is being tried against every internet-facing target, so the federal timeline is a sensible ceiling for everyone.