CISA adds CVE-2026-33634 to KEV and orders FCEB mitigations
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2026-33634 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply mitigations by April 9, 2026. The move turns the issue into a federal remediation priority and sets a firm deadline for reducing exposure. It matters because the listing compels agencies to act on a vulnerability deemed significant enough for mandated federal response.
Related Happenings
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Public Sector Action
H score59
First: 15.05.2026 08:28
Last: 15.05.2026 08:28
Sources 1
About this happening:
CISA added CVE-2026-20182 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to remediate Cisco Catalyst SD-WAN Controller by May 17,...
CISA KEV remediation order for Cisco Catalyst SD-WAN Controller CVE-2026-20182
Public Sector ActionAbout this happening: CISA added CVE-2026-20182 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to remediate Cisco Catalyst SD-WAN Controller by May 17,...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV listing and FCEB firewall directive for CVE-2026-0300
Public Sector Action
H score64
First: 07.05.2026 13:57
Last: 07.05.2026 13:57
Sources 1
About this happening:
CISA added CVE-2026-0300 to the KEV Catalog and ordered FCEB agencies to secure vulnerable firewalls by May 9, 2026. The federal directive makes the exploited...
CISA KEV listing and FCEB firewall directive for CVE-2026-0300
Public Sector ActionAbout this happening: CISA added CVE-2026-0300 to the KEV Catalog and ordered FCEB agencies to secure vulnerable firewalls by May 9, 2026. The federal directive makes the exploited...
Timeline
-
13.04.2026 09:50 2 articles · 3mo ago
CISA adds CVE-2026-33634 to KEV
Legal Policy Action UpdateCISA added CVE-2026-33634 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply the necessary mitigations by April 9, 2026, turning the issue into a federal remediation deadline.
Show sources
- OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident — thehackernews.com — 13.04.2026 09:50
- OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident — thehackernews.com — 13.04.2026 09:50