Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

A quiet KEV fortnight, then a 2008 bug

2 min read
12:09UTC

CISA's Known Exploited Vulnerabilities catalogue added seven low-profile CVEs between 5 and 14 July, capped by an 18-year-old Cisco IOS flaw.

TechnologyDeveloping
Key takeaway

A quiet KEV fortnight is ambiguous: a genuine exploitation lull or a triage doctrine, not yet separable.

CISA's Known Exploited Vulnerabilities (KEV) catalogue, the US register of flaws confirmed under active exploitation, added seven CVEs between 5 and 14 July, none from a headline enterprise-security vendor 1. Six sit in web software: four Joomla extensions, the AI-app builder Langflow, and Adobe ColdFusion, with no Cisco, Fortinet, Microsoft or Ivanti entry among them. The seventh breaks the pattern: CVE-2008-4128, an 18-year-old cross-site request forgery (CSRF) flaw in Cisco IOS, added on Monday 13 July.

The catalogue stood at 1,638 entries on 14 July, up from 1,585 at the end of April, roughly 53 additions in ten weeks 2. April alone added 16 in 13 days. CVE-2008-4128 is the oldest KEV entry this beat has tracked, extending the ancient-revival thread that ran through a 17-year-old Office bug in April .

Two readings fit the slowdown, and a single fortnight cannot separate them. Either confirmed active exploitation genuinely eased over the summer, or BOD 26-04, the risk-tiered directive that replaced patch-everything rules in June , is already reshaping what gets listed and how fast. The fortnight-of-triage note two weeks ago raised the same question. KEV feeds patch prioritisation in tools like Qualys, Tenable and Rapid7, so any editorial shift behind the listings propagates into every enterprise treating the feed as ground truth. Ten weeks is too short to credit a doctrine shift, so this stays a hypothesis to watch.

Deep Analysis

In plain English

CISA, the US government's cyber-security agency, keeps a public list called the Known Exploited Vulnerabilities catalogue: software and hardware flaws that criminals are actually using in real attacks, rather than theoretical weaknesses. This fortnight was quiet: only seven new entries, six in ordinary web software. The odd one out was an 18-year-old bug in Cisco's router software, first found in 2008, only now confirmed as being actively exploited, which means some Cisco routers out there are still running software old enough to vote.

Deep Analysis
Root Causes

CISA lists a flaw on the KEV catalogue once there is evidence of active exploitation, not at the point of disclosure. CVE-2008-4128 sat off the catalogue for eighteen years because nobody had evidence it was being exploited in the wild.

Its addition this fortnight means that evidence now exists, most likely against unsupported, end-of-life Cisco IOS devices that were never going to receive the 2008 patch through a normal vendor update cycle.

First Reported In

Update #10 · One operator worked both ransomware brands

CISA· 14 Jul 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.