CISA adds Three Vulnerabilities to KEV Catalog

CISA adds Three Vulnerabilities to KEV Catalog

Overview CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation — CVE-2022-0492, a Linux Kernel Improper Authentication vulnerability, and CVE-2025-48595,…
Android Framework Zero-Days Hit CISA KEV

Android Framework Zero-Days Hit CISA KEV

CISA added two high-severity Android Framework vulnerabilities—CVE-2025-48572 and CVE-2025-48633—to its Known Exploited Vulnerabilities (KEV) catalog on December 1, 2025, confirming limited, targeted exploitation in the wild. These zero-days, addressed in…