THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a critical resource for the cybersecurity community. It lists vulnerabilities exploited in the wild, helping organizations prioritize their vulnerability management efforts. The latest entry is CVE-2026-8037, which is a command injection vulnerability in Progress LoadMaster that allows unauthenticated attackers to execute arbitrary commands.
Organizations are encouraged to implement vendor-provided mitigations in accordance with CISA guidelines, particularly BOD 26-04. The KEV Catalog is available in various formats including CSV and JSON, and users can subscribe for updates.