This page may contain stale information. Last updated: 2026-05-04
Overview
CISA (Cybersecurity and Infrastructure Security Agency) is the United States federal agency responsible for protecting the nation’s critical infrastructure from physical and cyber threats. Established in 2018, CISA operates under the Department of Homeland Security.
Known Exploited Vulnerabilities Catalog
CISA maintains a catalog of vulnerabilities known to be actively exploited by threat actors. Federal agencies and critical infrastructure operators are required to remediate cataloged vulnerabilities on strict timelines.
Key Features
- Mandatory Remediation: Federal agencies must patch within deadlines
- Public Reference: Organizations can check if they’re affected
- Active Exploitation Required: Only vulnerabilities with evidence of active exploitation are added
2026 Notable Additions
- cPanel CVE-2026-41940: Critical authentication bypass vulnerability affecting millions of web servers