Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

A quiet KEV fortnight, then a 2008 bug

2 min read
16:08UTC

CISA's Known Exploited Vulnerabilities catalogue added seven low-profile CVEs between 5 and 14 July, capped by an 18-year-old Cisco IOS flaw.

TechnologyDeveloping
Key takeaway

A quiet KEV fortnight is ambiguous: a genuine exploitation lull or a triage doctrine, not yet separable.

CISA's Known Exploited Vulnerabilities (KEV) catalogue, the US register of flaws confirmed under active exploitation, added seven CVEs between 5 and 14 July, none from a headline enterprise-security vendor 1. Six sit in web software: four Joomla extensions, the AI-app builder Langflow, and Adobe ColdFusion, with no Cisco, Fortinet, Microsoft or Ivanti entry among them. The seventh breaks the pattern: CVE-2008-4128, an 18-year-old cross-site request forgery (CSRF) flaw in Cisco IOS, added on Monday 13 July.

The catalogue stood at 1,638 entries on 14 July, up from 1,585 at the end of April, roughly 53 additions in ten weeks 2. April alone added 16 in 13 days. CVE-2008-4128 is the oldest KEV entry this beat has tracked, extending the ancient-revival thread that ran through a 17-year-old Office bug in April .

Two readings fit the slowdown, and a single fortnight cannot separate them. Either confirmed active exploitation genuinely eased over the summer, or BOD 26-04, the risk-tiered directive that replaced patch-everything rules in June , is already reshaping what gets listed and how fast. The fortnight-of-triage note two weeks ago raised the same question. KEV feeds patch prioritisation in tools like Qualys, Tenable and Rapid7, so any editorial shift behind the listings propagates into every enterprise treating the feed as ground truth. Ten weeks is too short to credit a doctrine shift, so this stays a hypothesis to watch.

Deep Analysis

In plain English

CISA, the US government's cyber-security agency, keeps a public list called the Known Exploited Vulnerabilities catalogue: software and hardware flaws that criminals are actually using in real attacks, rather than theoretical weaknesses. This fortnight was quiet: only seven new entries, six in ordinary web software. The odd one out was an 18-year-old bug in Cisco's router software, first found in 2008, only now confirmed as being actively exploited, which means some Cisco routers out there are still running software old enough to vote.

Deep Analysis
Root Causes

CISA lists a flaw on the KEV catalogue once there is evidence of active exploitation, not at the point of disclosure. CVE-2008-4128 sat off the catalogue for eighteen years because nobody had evidence it was being exploited in the wild.

Its addition this fortnight means that evidence now exists, most likely against unsupported, end-of-life Cisco IOS devices that were never going to receive the 2008 patch through a normal vendor update cycle.

First Reported In

Update #10 · One operator worked both ransomware brands

CISA· 14 Jul 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.