CISA adding seven vulnerabilities to the Known Exploited Vulnerabilities catalog should be treated as a real-world exploitation warning, not just another patching bulletin. CISA’s KEV catalog is based on evidence of active exploitation, which means these vulnerabilities are already being used by attackers, not merely discussed in vulnerability databases for people who enjoy collecting CVEs like trading cards.

The May 20, 2026 additions reportedly include a mix of old and new issues: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2026-41091, and CVE-2026-45498. Several of these are legacy Microsoft and Adobe vulnerabilities, while the newer entries include Microsoft Defender issues, with Canada’s Cyber Centre also noting that CISA added CVE-2026-41091 and CVE-2026-45498 to the KEV database on May 20, 2026. 
The important lesson is that old vulnerabilities do not become harmless just because they are old. Legacy systems, forgotten servers, outdated endpoints, unsupported software, and unpatched remote access paths continue to give attackers easy entry points. If a vulnerability from 2008, 2009, or 2010 is still being exploited in 2026, the problem is not only the vulnerability. The problem is poor asset visibility, weak patch governance, and the eternal human belief that “we’ll upgrade it later” is a security strategy.

Organizations should immediately review their exposure to these CVEs, especially in older Windows, Internet Explorer, DirectX, Adobe Acrobat/Reader, and Microsoft Defender environments. Security teams should prioritize KEV-listed flaws above generic CVSS-only queues, remove unsupported systems where possible, apply vendor updates or mitigations, isolate systems that cannot be patched, and monitor for signs of exploitation. 

The broader message is simple: vulnerability management must be risk-based and exploitation-driven. A KEV listing means attackers have already moved from theory to action. Businesses should not wait for ransomware, data theft, or lateral movement before discovering that an “old” system was still quietly running in the corner, doing what legacy systems do best: becoming someone else’s foothold.


CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CI

Source: CISA Adds Seven Known Exploited Vulnerabilities to Catalog via CISA Advisories — published 20 May 2026.