CISA Updates KEV Catalog with 4 Critical Vulnerabilities Following Ongoing Exploits
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalogue by including four critical security vulnerabilities affecting widely-used enterprise software and development tools.
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalogue by including four critical security vulnerabilities affecting widely-used enterprise software and development tools.
These vulnerabilities were added on Mon, Jan 22, 2026, with a compliance deadline set for Mon, Feb 12, 2026. Federal agencies and critical infrastructure operators are required to implement the necessary patches or mitigations by this date.
The vulnerabilities pose various threats, ranging from supply chain compromises to infrastructure orchestration platforms. Organizations using the impacted products should prioritize addressing these vulnerabilities to prevent unauthorized access, data exfiltration, and lateral movement within their networks.
Affected Products and Vulnerability Details
Vendor Product CVE ID Vulnerability Type Severity
Prettier eslint-config-prettier CVE-2025-54313 Embedded Malicious Code (CWE-506) Critical
These vulnerabilities were added on Mon, Jan 22, 2026, with a compliance deadline set for Mon, Feb 12, 2026.
Vite Vitejs CVE-2025-31125 Improper Access Control (CWE-200, CWE-284) Critical
Versa Concerto SD-WAN CVE-2025-34026 Improper Authentication (CWE-288) Critical
Synacor Zimbra Collaboration Suite CVE-2025-68645 PHP Remote File Inclusion (CWE-98) Critical
Organizations must promptly audit systems using the affected software versions. For Prettier eslint-config-prettier and Vite Vitejs, developers should assess package dependencies, revert to updated versions, and review CI/CD logs for any irregular activities.
Versa Concerto deployments require credential rotation and network segmentation analysis, especially for systems exposing administrative interfaces. Zimbra administrators are advised to apply vendor-provided security updates and implement web application firewall rules to limit access to vulnerable endpoints.
CISA emphasizes adherence to Binding Operational Directive 22-01 for federal agencies utilizing cloud services. Organizations should synchronize patch deployment across development, staging, and production environments and monitor for exploitation indicators such as unexpected process execution, unauthorized file access, and abnormal authentication patterns.
The expansion of the KEV Catalog highlights the intersection of development tool compromise and infrastructure vulnerabilities, necessitating coordinated incident response and proactive patch management across the software supply chain.
Based on reporting by GBHackers.
