Federal Civilian Executive Branch
Coverage of Federal Civilian Executive Branch in the Nexus archive.
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA added a critical SharePoint Server vulnerability (CVE-2026-58644) with a CVSS score of 9.8 to its KEV catalog, requiring FCEB agencies to patch by July 19, 2026. The flaw is a deserialization issue exploitable for remote code execution.
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
CISA added a vulnerability in LiteSpeed cPanel Plugin to its KEV catalog, requiring FCEB agencies to fix it by June 18, 2026. The flaw, CVE-2026-54420 (CVSS score 8.5), involves privilege escalation exploited for root access.
- CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
CISA has added CVE-2026-20182, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies are required to remediate the vulnerability by May 17, 2026.
- Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
A high-severity vulnerability (CVE-2026-34197) in Apache ActiveMQ Classic is being actively exploited, prompting CISA to add it to its KEV catalog with a CVSS score of 8.8. Federal civilian agencies are required to address the flaw immediately.