THE Known Exploited Vulnerabilities (KEV) Catalog, managed by CISA, serves as a key resource for cybersecurity practitioners, listing vulnerabilities actively exploited in the wild. Organizations are encouraged to utilize this catalog to enhance vulnerability management strategies. The catalog includes various formats for access, such as CSV and JSON.
A specific entry in the catalog details CVE-2026-20349, a heap inspection vulnerability affecting Cisco Secure Firewall products that could lead to a denial of service. The recommended action includes applying vendor mitigations and adhering to CISA's guidance on security updates.