Skip to content

Commit 650816b

Browse files
Update KEV: Thu May 14 00:36:06 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c030c0c commit 650816b

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

known_exploited_vulnerabilities.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2026.05.08",
4-
"dateReleased": "2026-05-08T17:31:07.6877Z",
3+
"catalogVersion": "2026.05.13",
4+
"dateReleased": "2026-05-13T17:58:37.3518Z",
55
"count": 1590,
66
"vulnerabilities": [
77
{
@@ -10,7 +10,7 @@
1010
"product": "LiteLLM",
1111
"vulnerabilityName": "BerriAI LiteLLM SQL Injection Vulnerability",
1212
"dateAdded": "2026-05-08",
13-
"shortDescription": "BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.",
13+
"shortDescription": "BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.",
1414
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
1515
"dueDate": "2026-05-11",
1616
"knownRansomwareCampaignUse": "Unknown",
@@ -41,7 +41,7 @@
4141
"vulnerabilityName": "Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability",
4242
"dateAdded": "2026-05-06",
4343
"shortDescription": "Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.",
44-
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required.",
44+
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5\/13\/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.",
4545
"dueDate": "2026-05-09",
4646
"knownRansomwareCampaignUse": "Unknown",
4747
"notes": "https:\/\/security.paloaltonetworks.com\/CVE-2026-0300 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-0300",

0 commit comments

Comments
 (0)