CISA adds eight exploited vulnerabilities to its KEV catalogue

Over five days CISA added eight vulnerabilities to its Known Exploited Vulnerabilities catalogue. The first batch, on 5 March, covered CVE-2017-7921 in Hikvision products, CVE-2021-22681 in Rockwell products, and CVE-2021-30952, CVE-2023-41974 and CVE-2023-43000 in Apple products. The second batch, on 9 March, added CVE-2021-22054 in Omnissa Workspace ONE, CVE-2025-26399 in SolarWinds Web Help Desk and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager.

What this means for your business

The striking part is the age. Several flaws date from 2017 and 2021 and are still being exploited, because the equipment sits where it was installed and nobody owns it. Cameras, industrial control and endpoint management tooling routinely fall between IT and operations. The KEV list is therefore a useful prioritisation list: this is not theoretical risk, these are flaws someone is actually using.

Berigo recommends

  • Treat the KEV catalogue as the standing first priority in vulnerability management, ahead of plain CVSS sorting.
  • Map camera surveillance, industrial control and endpoint management tooling in particular. They often lack a clear owner.
  • Set a deadline for equipment that can no longer be patched: either segment it off or replace it.
  • Prioritise Ivanti Endpoint Manager first; an authentication bypass in a management tool grants access to everything that tool controls.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch