Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

A quiet KEV fortnight, then a 2008 bug

2 min read
18:20UTC

CISA's Known Exploited Vulnerabilities catalogue added seven low-profile CVEs between 5 and 14 July, capped by an 18-year-old Cisco IOS flaw.

TechnologyDeveloping
Key takeaway

A quiet KEV fortnight is ambiguous: a genuine exploitation lull or a triage doctrine, not yet separable.

CISA's Known Exploited Vulnerabilities (KEV) catalogue, the US register of flaws confirmed under active exploitation, added seven CVEs between 5 and 14 July, none from a headline enterprise-security vendor 1. Six sit in web software: four Joomla extensions, the AI-app builder Langflow, and Adobe ColdFusion, with no Cisco, Fortinet, Microsoft or Ivanti entry among them. The seventh breaks the pattern: CVE-2008-4128, an 18-year-old cross-site request forgery (CSRF) flaw in Cisco IOS, added on Monday 13 July.

The catalogue stood at 1,638 entries on 14 July, up from 1,585 at the end of April, roughly 53 additions in ten weeks 2. April alone added 16 in 13 days. CVE-2008-4128 is the oldest KEV entry this beat has tracked, extending the ancient-revival thread that ran through a 17-year-old Office bug in April .

Two readings fit the slowdown, and a single fortnight cannot separate them. Either confirmed active exploitation genuinely eased over the summer, or BOD 26-04, the risk-tiered directive that replaced patch-everything rules in June , is already reshaping what gets listed and how fast. The fortnight-of-triage note two weeks ago raised the same question. KEV feeds patch prioritisation in tools like Qualys, Tenable and Rapid7, so any editorial shift behind the listings propagates into every enterprise treating the feed as ground truth. Ten weeks is too short to credit a doctrine shift, so this stays a hypothesis to watch.

Deep Analysis

In plain English

CISA, the US government's cyber-security agency, keeps a public list called the Known Exploited Vulnerabilities catalogue: software and hardware flaws that criminals are actually using in real attacks, rather than theoretical weaknesses. This fortnight was quiet: only seven new entries, six in ordinary web software. The odd one out was an 18-year-old bug in Cisco's router software, first found in 2008, only now confirmed as being actively exploited, which means some Cisco routers out there are still running software old enough to vote.

Deep Analysis
Root Causes

CISA lists a flaw on the KEV catalogue once there is evidence of active exploitation, not at the point of disclosure. CVE-2008-4128 sat off the catalogue for eighteen years because nobody had evidence it was being exploited in the wild.

Its addition this fortnight means that evidence now exists, most likely against unsupported, end-of-life Cisco IOS devices that were never going to receive the 2008 patch through a normal vendor update cycle.

First Reported In

Update #10 · One operator worked both ransomware brands

CISA· 14 Jul 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.