Skip to content

Commit c5e7bef

Browse files
Update KEV: Fri May 29 00:40:38 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent d1bdedf commit c5e7bef

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

known_exploited_vulnerabilities.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2026.05.27",
4-
"dateReleased": "2026-05-27T17:08:41.0638Z",
3+
"catalogVersion": "2026.05.28",
4+
"dateReleased": "2026-05-28T16:27:12.9227Z",
55
"count": 1606,
66
"vulnerabilities": [
77
{
@@ -13,7 +13,7 @@
1313
"shortDescription": "Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.",
1414
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
1515
"dueDate": "2026-06-10",
16-
"knownRansomwareCampaignUse": "Unknown",
16+
"knownRansomwareCampaignUse": "Known",
1717
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https:\/\/github.com\/nrwl\/nx-console\/security\/advisories\/GHSA-c9j4-9m59-847w ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-48027",
1818
"cwes": [
1919
"CWE-506"
@@ -28,7 +28,7 @@
2828
"shortDescription": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.",
2929
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
3030
"dueDate": "2026-06-10",
31-
"knownRansomwareCampaignUse": "Unknown",
31+
"knownRansomwareCampaignUse": "Known",
3232
"notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https:\/\/github.com\/TanStack\/router\/security\/advisories\/GHSA-g7cv-rxg3-hmpx ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-45321",
3333
"cwes": []
3434
},

0 commit comments

Comments
 (0)