Timeline
CISA
US federal cyber lead; runs the KEV catalogue with mandatory federal patch deadlines.
57 of 57 entries (52 events, 5 interactions)
Filters
#12 29 Jul
Published a 30 July alert telling water utilities to disconnect exposed controllers
Cybersecurity: Threats and Defences: Water plants told to unplug controllers#12 29 Jul
Mentioned in: The alert's citations predate the alert
Cybersecurity: Threats and Defences#12 28 Jul
Compressed federal KEV patch deadlines to a three-day median since June
Cybersecurity: Threats and Defences: KEV patch clocks fell to three days#12 28 Jul
Catalogued three new vulnerabilities across three vendors within ten days
Cybersecurity: Threats and Defences: Arista, Fortinet and Cisco flaws listed#12 26 Jul
Mentioned in: One firm hedged, heise online named APT28
Cybersecurity: Threats and Defences#11 23 Jul
Co-published joint advisory AA26-204A
Cybersecurity: Threats and Defences: Zimbra preview leaks mail to Russia#11 22 Jul
Listed two SharePoint deserialization CVEs on 16 and 22 July
Cybersecurity: Threats and Defences: SharePoint stays under active KEV fire#11 21 Jul
Added the second Langflow flaw to KEV on 21 July
Cybersecurity: Threats and Defences: Langflow hits KEV a second time#11 16 Jul
Added the flaw to KEV on 16 July, a month after detection
Cybersecurity: Threats and Defences: CISA's KEV list runs a month late#11 15 Jul
Set a three-day patch deadline for Oracle E-Business Suite
Cybersecurity: Threats and Defences: Oracle EBS gets a 3-day patch clock#10 14 Jul
Added seven CVEs to the KEV catalogue over the fortnight
Cybersecurity: Threats and Defences: A quiet KEV fortnight, then a 2008 bug#9 4 Jul
Added six actively exploited CVEs to KEV across three updates this fortnight
Cybersecurity: Threats and Defences: BOD 26-04, a fortnight of triage#9 1 Jul
Added CVE-2026-45659 to the KEV catalogue with a three-day FCEB deadline
Cybersecurity: Threats and Defences: SharePoint patch clock runs out today#9 1 Jul
Flagged the FortiBleed credential set as privately held
Cybersecurity: Threats and Defences: Lynx crew cashes in FortiBleed haul#9 1 Jul
Updated the CVE-2026-33825 KEV entry to confirm ransomware exploitation for SYSTEM access
Cybersecurity: Threats and Defences: BlueHammer turns into a ransomware step#9 29 Jun
Added five vulnerabilities across two KEV batches in a fortnight
Cybersecurity: Threats and Defences: Cisco tops a five-vendor KEV batch#8 23 Jun
Added all three CVEs to KEV on 23 June with a 26 June 3-day deadline
Cybersecurity: Threats and Defences: Triple CVSS-10 Ubiquiti chain hits root#8 22 Jun
Co-issued the Five Eyes AI cyber-risk statement on 22 June 2026
Cybersecurity: Threats and Defences: Five Eyes warn AI threat is months away#8 18 Jun
Issued joint alert on 18 June recommending hardening of Fortinet devices
Cybersecurity: Threats and Defences: 86,644 Fortinet logins become a hit list#8 18 Jun
Added CVE-2026-20253 to KEV on 18 June with a 21 June federal deadline
Cybersecurity: Threats and Defences: Splunk lands its first-ever KEV entry#8 17 Jun
Mentioned in: A handle keeps dropping MS zero-days
Cybersecurity: Threats and Defences#8 10 Jun
Revoked BOD 22-01 and issued risk-tiered replacement BOD 26-04
Cybersecurity: Threats and Defences: CISA tears up its KEV deadline rules#12 9 Jun
Phase II asks agencies for paperwork
Cybersecurity: Threats and Defences#7 9 Jun
Mentioned in: 200 fixes, six zero-days, late Exchange
Cybersecurity: Threats and Defences#7 9 Jun
Added CVE-2026-7473 to KEV catalogue with 23 June federal deadline despite no vendor patch
Cybersecurity: Threats and Defences: Arista refuses to patch KEV flaw#7 8 Jun
Added CVE-2026-50751 to KEV catalogue with 11 June three-day federal deadline
Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patch#7 5 Jun
Added CVE-2026-28318 to KEV on 5 June with 19 June federal deadline, flagging ransomware risk
Cybersecurity: Threats and Defences: SolarWinds Serv-U back on KEV list#6 3 Jun
Listed CVE-2026-45247 to the KEV catalogue with a 6 June federal deadline
Cybersecurity: Threats and Defences: Magento RCE forces 9-day patch race#6 2 Jun
Added CVE-2022-0492 and CVE-2025-48595 to the KEV catalogue on 2 June with a 5 June deadline
Cybersecurity: Threats and Defences: Old Linux container bug back in the wild#6 1 Jun
Listed CVE-2024-21182 to the KEV catalogue on 1 June with a 22 June deadline
Cybersecurity: Threats and Defences: WebLogic flaw revived as ransomware vector#5 22 May
Added CVE-2026-9082 to KEV on 22 May with a five-day federal deadline of 27 May
Cybersecurity: Threats and Defences: Drupal SQL flaw hits PostgreSQL sites#5 21 May
Added CVE-2025-34291 and CVE-2026-34926 to KEV on 21 May with a 4 June deadline
Cybersecurity: Threats and Defences: AI orchestration flaw joins CISA's KEV#5 18 May
Added CVE-2026-48027 to KEV on 27 May and issued Alert AA26-148A on 28 May
Cybersecurity: Threats and Defences: GitHub's own code cloned via add-on#4 15 May
Added CVE-2026-42897 to KEV on 15 May with a 29 May federal remediation deadline before a patch existed
Cybersecurity: Threats and Defences: Exchange repeats the CISA deadline-before-patch trap#4 14 May
Added CVE-2026-20182 to KEV on 14 May and issued Emergency Directive ED 26-03 with a 3-day federal remediation deadline
Cybersecurity: Threats and Defences: UAT-8616 keeps Cisco SD-WAN under fire#4 13 May
Added CVE-2026-20182 and CVE-2026-42897 to KEV within 48 hours of the 13 May Patch Tuesday release
Cybersecurity: Threats and Defences: Patch Tuesday clean streak hides out-of-band KEVs#4 8 May
Added CVE-2026-42208 to the KEV catalogue on 8 May 2026
Cybersecurity: Threats and Defences: LiteLLM SQL injection hits in 36 hours#3 7 May
Added CVE-2026-6973 to KEV on 7 May with 10 May federal deadline
Cybersecurity: Threats and Defences: Ivanti EPMM logs fourth KEV zero-day since 2023#3 6 May
Added CVE-2026-0300 to KEV on 6 May with 9 May deadline
Cybersecurity: Threats and Defences: CISA deadline for PAN-OS RCE lands four days early#3 30 Apr
Added CVE-2026-41940 to KEV on 30 April with 3 May federal deadline
Cybersecurity: Threats and Defences: cPanel zero-day ran 65 days before patch; Sorry ransomware active#2 28 Apr
Mentioned in: Scattered Spider's Bouquet arrested in Helsinki
Cybersecurity: Threats and Defences#2 24 Apr
Co-published joint advisory AA26-113A disclosing FIRESTARTER implant and remediation guidance
Cybersecurity: Threats and Defences: FIRESTARTER implant survives every Cisco firewall patch#2 24 Apr
Disclosed that a federal agency remained compromised six months post-patch
Cybersecurity: Threats and Defences: Federal agency stayed compromised six months#2 23 Apr
Co-signed 16-agency advisory naming Raptor Train and KV Botnet operators
Cybersecurity: Threats and Defences: Sixteen agencies put IOC extinction in print#2 23 Apr
Mentioned in: Norway joins the Salt Typhoon victim list
Cybersecurity: Threats and Defences#2 20 Apr
Added three Cisco Catalyst SD-WAN Manager CVEs to KEV with a three-day federal remediation deadline
Cybersecurity: Threats and Defences: CISA gives Cisco SD-WAN three days to patch#3 16 Apr
Mentioned in: CL-STA-1132 exploited PAN-OS since 16 April, log destruction confirmed
Cybersecurity: Threats and Defences#1 14 Apr
Added CVE-2009-0238 to the KEV catalogue on 14 April 2026 marking it as actively exploited
Cybersecurity: Threats and Defences: 17-year-old Office RCE back on KEV#1 14 Apr
#1 14 Apr
#1 7 Apr
Trump proposes $707m CISA cut, 860 jobs
Cybersecurity: Threats and Defences#1 7 Apr
“proposed budget cut”
Cybersecurity: Threats and Defences · source event
#1 28 Mar
Added CVE-2025-53521 to KEV on 28 March 2026
Cybersecurity: Threats and Defences: F5 reclassifies DoS bug to 9.8 RCE#1 28 Mar
“added to kev catalogue”
Cybersecurity: Threats and Defences · source event
#1 23 Mar
Added CVE-2026-3055 to the Known Exploited Vulnerabilities catalogue on 28 March with 2 April FCEB patch deadline
Cybersecurity: Threats and Defences: CitrixBleed 3 lands on SAML broker#1 1 Feb
Assessed with high confidence that Volt Typhoon was pre-positioning in US CNI IT networks for OT lateral movement
Cybersecurity: Threats and Defences: FBI: Salt Typhoon still very much live#1 1 Feb
“assessed pre positioning threat”
Cybersecurity: Threats and Defences · source event