Vulnerability Management CISA adds Cisco IOS flaw to known exploited vulnerabilities catalog July 13, 2026 Share By SC Staff As reported by Security Affairs, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Cisco IOS flaw, identified as CVE-2008-4128, to its catalog of Known Exploited Vulnerabilities (KEV). This action mandates federal agencies to address the vulnerability by a specific deadline. The vulnerability, affecting Cisco IOS 12.4 on Cisco 871 Integrated Services Routers, involves multiple cross-site request forgery (CSRF) flaws within the HTTP Administration interface. Attackers can exploit these weaknesses to trick authenticated administrators into executing arbitrary commands, potentially leading to device compromise. The flaws allow for the execution of commands like "show privilege" and "alias exec" through specific URIs. CISA has issued Binding Operational Directive 22-01, requiring federal agencies to remediate this vulnerability by July 13, 2026, to mitigate the significant risk posed by its exploitation. Private organizations are also strongly encouraged to review the KEV catalog and address any identified vulnerabilities within their own infrastructure to enhance overall cybersecurity posture. Source: Security Affairs SC Staff Related Asset Management How to Evaluate Vulnerability & Exposure Management Platforms SC Media Editorial Intelligence, reviewed by Omkar Nimbalkar July 13, 2026 Choose a solution that reduces exposure—not just finds vulnerabilities Vulnerability Management CISA adds iCagenda and Balbooa Forms vulnerabilities to known exploited catalog SC Staff July 13, 2026 The vulnerabilities, CVE-2026-48939 affecting iCagenda and CVE-2026-56291 affecting Balbooa Forms, both allow for unrestricted file uploads. Vulnerability Management Six U-Boot vulnerabilities could allow stealthy firmware attacks SC Staff July 13, 2026 The vulnerabilities, found in U-Boot's FIT signature verification code, range from denial of service to arbitrary code execution. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds