Most executives think the Known Exploited Vulnerabilities catalog is an IT problem. Across July, August, and early September 2026, the insurance and incident-response markets turned it into a liability problem.

When CISA adds a vulnerability to its KEV catalog, it is confirming active exploitation in the wild. Over this period, cyber insurers and incident-response firms started citing that catalog by name in their own advisories, while CISA added exploited flaws in Oracle, SonicWall, Microsoft, Citrix, and VMware. The moment a flaw lands on the list and you are running the affected software, you are on notice. That language matters in a coverage dispute, in litigation, and in the diligence memo on your next transaction.

Host David Shaw (CISSP, GLEG) breaks down what changed, why it keeps happening, and what to do about it.

In this episode:

  • Why the KEV catalog moved from a federal compliance tool to a market-facing liability standard
  • The exploited flaws driving that shift across July, August, and early September: Oracle E-Business Suite Payments (CVE-2026-46817), SonicWall SMA1000 (CVE-2026-15409 / CVE-2026-15410 and CVE-2026-83548 / CVE-2026-83549), Microsoft AD FS and SharePoint, VMware vCenter (CVE-2026-59310), and a CitrixBleed-class NetScaler flaw (CVE-2026-8451)
  • How insurers build a documented record of what you “should have known”
  • What KEV exposure means in M&A diligence, rep and warranty coverage, and escrow
  • The vendor-risk lesson from the Suno breach

The conversations to have this week:

  1. Ask your IT lead or MSP: do you monitor the CISA KEV catalog, and what is our SLA for patching a KEV-listed flaw on an internet-facing system?
  2. Ask your insurer or broker: does our policy make timely patching of known exploited vulnerabilities a condition of coverage?
  3. If you are a PE operator or involved in a deal, ask your diligence team or deal counsel: are any target systems running KEV-listed versions, and is there documentation of remediation?

Sources referenced:

The Rook is board-ready security intelligence for founders, PE operating partners, M&A attorneys, and executives who own security risk without a dedicated security function. New episodes every other Tuesday.

Work with David: corvus-cyber.com

Now, it’s your move.