Back to Feed
VulnerabilitiesMay 27, 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA adds three actively exploited vulnerabilities to KEV Catalog including Daemon Tools, TanStack, and Nx Console

Summary

CISA has added three CVEs to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: CVE-2026-8398 (Daemon Tools Lite embedded malicious code), CVE-2026-45321 (TanStack unspecified vulnerability), and CVE-2026-48027 (Nx Console embedded malicious code). These additions fall under BOD 22-01 requirements, which mandate Federal Civilian Executive Branch agencies to remediate identified vulnerabilities by specified deadlines. CISA urges all organizations to prioritize patching these actively exploited flaws as part of their vulnerability management practices.

Full text

Alert CISA Adds Three Known Exploited Vulnerabilities to Catalog Release DateMay 27, 2026 CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-45321 TanStack Unspecified Vulnerability CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy. Please share your thoughts We recently updated our anonymous product survey; we welcome your feedback.

Indicators of Compromise

  • cve — CVE-2026-8398
  • cve — CVE-2026-45321
  • cve — CVE-2026-48027

Entities

CISA (vendor)Daemon Tools Lite (product)TanStack (product)Nx Console (product)