CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-21385 affecting Qualcomm chipsets (memory corruption) and CVE-2026-22719 affecting Broadcom VMware Aria Operations (command injection). These vulnerabilities are actively being exploited by threat actors and pose significant risks to federal networks, with remediation required for Federal Civilian Executive Branch agencies under BOD 22-01.
Summary
CISA has added two newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-21385 affecting Qualcomm chipsets (memory corruption) and CVE-2026-22719 affecting Broadcom VMware Aria Operations (command injection). These vulnerabilities are actively being exploited by threat actors and pose significant risks to federal networks, with remediation required for Federal Civilian Executive Branch agencies under BOD 22-01.
Indicators of Compromise
- cve — CVE-2026-21385
- cve — CVE-2026-22719