Five additions to CISA’s exploited-vulnerability catalogue sharpened the patch queue.
What happened. CISA added flaws affecting Adminer, Cisco IOS and IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and Sudo after finding evidence of active exploitation.
Impact and confidence
The catalogue establishes exploitation, not how many organizations were compromised. Product presence and exposure still determine local urgency.
Defensive takeaway
Reconcile the five CVEs against an authoritative asset inventory. Treat absence of an asset match as an evidence result, not an assumption.