CISA's Known Exploited Vulnerabilities catalog reads like a threat actor's hit list — and some organizations still haven't patched entries from 2021. This episode breaks down the most dangerous active CVEs, from Fortinet and Joomla to Log4Shell, and what the patterns reveal.
Show Notes
CISA's Known Exploited Vulnerabilities (KEV) catalog is one of the most actionable threat-intelligence resources available to security teams — and one of the most underused. This episode of Cybersecurity digs into the catalog's current entries, spotlighting the specific vulnerabilities that should be at the top of every organization's patch queue right now, based on RMA's analysis of the most dangerous known exploited vulnerabilities. From newly added critical flaws to ransomware-tagged entries that have lingered for years, the picture that emerges is both urgent and instructive.
Here's what the episode covers:
- What the KEV catalog actually means: How CISA's confirmed-exploitation standard differs from CVSS scores alone, and why KEV entries carry mandatory remediation deadlines for federal agencies — and should be treated as top priority everywhere else.
- The severity cluster at the top: The overwhelming majority of recent additions are rated Critical — remote code execution, authentication bypass, OS command injection — not edge-case bugs but direct breach vectors. Fortinet FortiSandbox and Adobe ColdFusion are among the newest and most alarming additions.
- The Joomla ecosystem signal: Multiple CVEs across Joomla-adjacent products landed on the catalog in rapid succession, a pattern that suggests threat actors have deliberately turned their attention to that platform and are systematically probing it. Third-party plugins remain the weakest link.
- Ransomware-tagged entries demand immediate action: Check Point Security Gateway, Oracle PeopleSoft, and PTC Windchill are all flagged as ransomware-associated — meaning CISA has confirmed links to active ransomware campaigns, raising the stakes well beyond standard patch prioritization. Effective vulnerability management means treating these as fire drills, not backlog items.
- Enterprise staples that keep reappearing: Ivanti, Splunk, and Cisco — across Unified Communications Manager and Catalyst SD-WAN Manager — continue to surface on the KEV list because their ubiquity makes them high-value, and their complexity makes them slow to patch.
- Old vulnerabilities don't retire: Log4Shell (2021) and MOVEit Transfer (2023) are still actively exploited. Attackers maintain lists of unpatched systems and return to them; defenders who assume remediation is "handled" are often wrong.
The episode closes with four concrete principles for security leaders: prioritize speed over perfection when KEV entries drop, watch ecosystems not just individual CVEs, treat ransomware-tagged entries as the highest-urgency signal in your queue, and audit the long tail of older vulnerabilities that may have been deprioritized or missed. For listeners who want to explore related threat vectors, the episode Initial Access Vectors You're Probably Ignoring in Your Security Plan pairs well with this discussion. The full KEV catalog with remediation guidance and prioritization context is available through RMA's known exploited vulnerabilities tracker.
RMA
What is SEC.co Podcast ?
A podcast about latest trends, techniques and learnings in cybersecurity and cyberdefense.