CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including issues affecting SonicWall SMA1000 Appliances and Microsoft Active Directory Federation Services and SharePoint Server. These vulnerabilities are actively exploited by malicious actors and pose significant risks. CISA is reinforcing its Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize the rapid remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets.