CISA KEV listing and FCEB ActiveMQ patch order
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2026-34197 to the KEV Catalog and ordered FCEB agencies to patch Apache ActiveMQ servers within two weeks. The directive sets a hard April 30 deadline under BOD 22-01. It matters because the flaw is actively exploited and affects widely exposed government infrastructure.
Related Happenings
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
Pentagon suspends CMMC phase two for 60-day review
Public Sector Action
H score24
First: 14.07.2026 09:37
Last: 14.07.2026 09:37
Sources 1
About this happening:
The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
Pentagon suspends CMMC phase two for 60-day review
Public Sector ActionAbout this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
Timeline
-
17.04.2026 12:30 1 articles · 2mo ago
Apache maintainers patch CVE-2026-34197 in ActiveMQ Classic
Mitigation Patch UpdateApache maintainers patched CVE-2026-34197 on March 30 in ActiveMQ Classic versions 6.2.3 and 5.19.4 after the flaw was found to stem from improper input validation that could let authenticated threat actors execute arbitrary code via injection attacks.
Show sources
- CISA flags Apache ActiveMQ flaw as actively exploited in attacks — www.bleepingcomputer.com — 17.04.2026 12:30
-
17.04.2026 12:30 2 articles · 2mo ago
CISA adds CVE-2026-34197 to KEV and orders FCEB patching
Legal Policy Action UpdateOn April 17, CISA added CVE-2026-34197 to its Known Exploited Vulnerabilities (KEV) Catalog, warned that Apache ActiveMQ is actively exploited in attacks, and ordered Federal Civilian Executive Branch (FCEB) agencies to patch ActiveMQ servers within two weeks, by April 30, under Binding Operational Directive (BOD) 22-01.
Show sources
- CISA flags Apache ActiveMQ flaw as actively exploited in attacks — www.bleepingcomputer.com — 17.04.2026 12:30
- Actively exploited Apache ActiveMQ flaw impacts 6,400 servers — www.bleepingcomputer.com — 21.04.2026 14:17