CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on March 5, 2026, stating that each has been confirmed to be actively exploited. The catalog is not advisory: under binding operational directives, federal civilian agencies must remediate KEV-listed flaws by set deadlines — generally two to three weeks — and the rest of the security industry treats those dates as the de facto global patch clock. A follow-up addition of one more exploited vulnerability came on March 18, keeping the month's cadence busy.
What is the KEV catalog?
A running list of vulnerabilities CISA has evidence of being exploited in the wild, drawn from vendor advisories, researcher reports, and the agency's own incident work. Since 2021, directives have instructed federal agencies to patch every catalog entry within published timelines. For private organizations, the catalog functions as a free, continuously updated "what attackers are actually using" feed — a short list that cuts through the thousands of CVEs published each year to the dozens that matter.
Which flaws were added in March?
Per CISA's March 5, 2026 announcement, five vulnerabilities across affected products were added based on evidence of active exploitation; the individual entries — CVE identifiers, products, versions, and due dates — are published in the catalog itself. A sixth addition followed on March 18. This report does not enumerate the specific CVEs beyond CISA's announcement, since entry-level detail and any revised due dates belong to the catalog as the source of record.
What should you do now?
- Check the catalog against your inventory. Search the KEV catalog for the vendors you run — network equipment, VPNs, file transfer tools, and anything internet-facing come first.
- Patch listed items immediately, not on the federal calendar but on your own urgency: actively exploited means someone is trying these flaws against random targets right now.
- Subscribe or automate. The catalog ships as JSON, and most vulnerability scanners and patch tools can ingest it directly — configure one of them so future additions reach you without anyone remembering to look.
- Use it to prioritize the backlog. If a full patch program feels impossible, the KEV list is the triage order: internet-facing KEV items first, internal KEV items second, everything else after.
The catalog's steady growth — additions arrive most weeks — is the honest state of the internet's maintenance debt. The organizations that fare best are not those with zero vulnerabilities, which do not exist, but those for whom a March 5 addition is a March 6 patch.
For more context, read Microsoft's April 2026 Patch Tuesday fixes 163 bugs, including two exploited zero-days.
For more context, read cisa emergency directive ed 26-03.
For more context, read microsoft patch tuesday january 2026.

