CISA added a vulnerability disclosed eighteen years ago to its catalog: a CSRF in the web panel of Cisco IOS. Eighteen years later, it's an active attack. The catalog counts only witnessed attacks. The remediation deadline is July 16 - three days after the announcement.
- CVE-2008-4128 (Cisco IOS, CSRF in the web interface) entered CISA's KEV catalog on July 13, 2026.
- It's the only addition for the day. The remediation deadline is July 16, 2026.
- CSRF: if the administrator is logged into the web panel and opens a planted link, the actions execute with his privileges.
The KEV catalog isn't a list of dangerous holes. There are thousands of dangerous holes and they mean nothing on their own. KEV is a list of holes for which an attack has been WITNESSED. So once something lands there, the question isn't the score on the scale. The question is exactly where you have it turned on.
Eighteen years. Stop on that number for a second. Nobody discovered anything new - the hole has sat described since 2008. The only thing that changed is that somewhere there are now enough devices with the web panel turned on to make the attack worth it. This is the router in the corner of the office that's been running for years and nobody touches - precisely because it works.
The practical move isn't a patch, it's an inventory. Check what you actually have turned on, and which administrative panel on it faces outward. CISA gives federal agencies three days. Not because closing it is hard - it's hard to find the devices in the first place.