---
title: "CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities"
url: https://daily.dev/posts/cisa-updates-kev-catalog-with-four-actively-exploited-software-vulnerabilities-io0g6rhpn
source_url: https://thehackernews.com/2026/01/cisa-updates-kev-catalog-with-four.html
type: article
source: "The Hacker News"
published: 2026-01-23T15:32:43.175Z
updated: 2026-08-24T07:08:09.427Z
tags: ["cyber", "vulnerability", "npm"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities

**[The Hacker News](https://daily.dev/sources/thn)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA added four actively exploited vulnerabilities to its KEV catalog: a PHP remote file inclusion flaw in Zimbra Collaboration Suite, an authentication bypass in Versa Concerto SD-WAN, an improper access control issue in Vite, and embedded malicious code in eslint-config-prettier from a supply chain attack. The eslint vulnerability stems from a phishing campaign that compromised maintainer credentials to publish trojanized npm packages. U.S. federal agencies must apply fixes by February 12, 2026, with exploitation of the Zimbra vulnerability confirmed since January 14, 2026.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/cisa-updates-kev-catalog-with-four.html>

## Similar posts on daily.dev

- [CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git](https://daily.dev/posts/cisa-adds-three-exploited-vulnerabilities-to-kev-catalog-affecting-citrix-and-git-r5fsdvugn) · The Hacker News · 2 upvotes · 0 comments
- [CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence](https://daily.dev/posts/cisa-adds-gladinet-and-cwp-flaws-to-kev-catalog-amid-active-exploitation-evidence-jsd8w3l6v) · The Hacker News · 0 upvotes · 0 comments
- [2025 CISA KEV Catalog Hits 1,484 Exploited Vulnerabilities](https://daily.dev/posts/2025-cisa-kev-catalog-hits-1-484-exploited-vulnerabilities-m08euiqm7) · Cyble · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#vulnerability](https://daily.dev/tags/vulnerability), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/cisa-updates-kev-catalog-with-four-actively-exploited-software-vulnerabilities-io0g6rhpn)
