What Happened
CISA recently added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-42016 and CVE-2026-42018 affecting JFrog Artifactory, and CVE-2026-84869 affecting ConnectWise ScreenConnect. All three are actively exploited.
While the Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize these vulnerabilities, CISA encourages all organizations to adopt this risk-based approach.
Timeline
Though CISA didn't detail the timeline for these vulnerabilities, the KEV Catalog addition process is consistent:
- Vulnerability disclosed and assigned a CVE ID.
- Evidence of active exploitation emerges.
- CISA evaluates against KEV criteria: confirmed exploitation, available CVE, and remediation guidance.
- Vulnerability added to KEV Catalog.
- Federal agencies have 30 days to remediate high-risk KEV vulnerabilities on publicly exposed assets under BOD 26-04.
Private organizations often lag, prioritizing by CVSS score alone and patching when feasible. This delay creates a window for attackers.
Which Controls Failed or Were Missing
If breached through these vulnerabilities, consider these failures:
Vulnerability Management Program Design: Your process may not be risk-based. Prioritizing by CVSS score without considering active exploitation evidence is ineffective.
Asset Inventory and Classification: Without an accurate inventory, you can't prioritize publicly exposed assets. Many organizations realize their exposure only after an incident.
Patch Management Cadence: If your patch timeline exceeds the KEV listing-to-exploitation window, you're vulnerable. BOD 26-04 requires a 30-day remediation for high-risk vulnerabilities on exposed assets. Quarterly cycles give attackers too much time.
Threat Intelligence Integration: Without integrating external threat intelligence or the KEV Catalog, you're treating all critical vulnerabilities equally, missing those with confirmed exploitation.
Compromise Assessment: BOD 26-04 requires checking for compromise before patching. If you skip this, you might be closing the door after the attacker is inside.
What the Relevant Standards Require
NIST Cybersecurity Framework: Maintain an accurate asset inventory and implement safeguards. Monitor for cybersecurity events and verify protective measures. A risk-based vulnerability management program aligns with these outcomes.
ISO 27001:2022 Control 8.8: Obtain timely information about vulnerabilities, evaluate exposure, and take measures. If you're waiting for a quarterly patch window despite confirmed exploitation, you're not meeting the control objective.
CIS Critical Security Controls v8, Control 7: Establish a remediation process addressing vulnerabilities by risk. Prioritize based on exploitability and impact. The KEV Catalog provides the necessary exploitability signal.
PCI DSS 4.0, Requirement 6.3.1: Identify and address vulnerabilities based on risk ranking. While PCI DSS doesn't explicitly reference KEV, a defensible methodology must account for active exploitation.
BOD 26-04 offers a clear benchmark: prioritize rapid remediation of vulnerabilities granting total control of publicly exposed assets, and check for compromise before patching.
Lessons and Action Items for Your Team
Integrate the KEV Catalog into your workflow. Don't wait for a mandate. Add the KEV Catalog feed to your platform or create a manual review process. When CISA adds a vulnerability, alert your team and start an assessment within 24 hours.
Redefine your patch prioritization matrix. CVSS scores measure theoretical severity. Your matrix should weigh KEV Catalog inclusion, public exposure, exploitation level, and impact on sensitive data or critical functions. A CVSS 7.5 with active exploitation evidence outranks a theoretical CVSS 9.8.
Establish a fast-track remediation process. If your patch cycle is 30 or 60 days, create an exception process for a 7-14 day timeline for KEV-listed vulnerabilities on internet-facing assets. Document criteria, get leadership buy-in, and test the process.
Maintain an accurate inventory of publicly exposed assets. Use external attack surface management tools, conduct regular port scans, and reconcile results against your CMDB. Update the inventory with new deployments.
Build compromise assessment into your patch process. Before patching a KEV-listed vulnerability, check logs for exploitation indicators. If you find evidence, shift to incident response.
Nominate vulnerabilities you discover being exploited. If you identify active exploitation not in the KEV Catalog, submit it via CISA's KEV Nomination Form. Your submission helps the broader community.
The KEV Catalog isn't just a federal compliance tool. It's a curated list of vulnerabilities attackers are exploiting now. If you're still prioritizing by CVSS score alone, you're addressing yesterday's problem while today's breach occurs.





