THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a critical resource for the cybersecurity community, allowing organizations to effectively manage vulnerabilities and stay updated on actively exploited vulnerabilities. Key features include:
1. **CVE-2026-34486**: A significant vulnerability in Apache Tomcat involving missing encryption of sensitive data, allowing for potential bypass of security measures.
2. **Mitigation Guidance**: Organizations are urged to apply vendor mitigations and adhere to CISA guidance, including BOD 26-04 for prioritizing security updates based on risk.
3. **Reporting New Vulnerabilities**: Stakeholders can nominate new vulnerabilities for inclusion in the catalog if they are aware of any not currently listed.
4. **Formats Available**: The KEV catalog can be accessed and downloaded in CSV, JSON, and print formats to accommodate different user needs.
5. **Subscriptions**: Users can subscribe to updates for the latest vulnerabilities to stay informed.