CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on January 22, 2026, confirming active exploitation across development tools, SD WAN infrastructure, email platforms, and package management systems. All four carry a February 12, 2026, remediation deadline under Binding Operational Directive 22-01.

The breadth of affected technology categories illustrates how threat actors maintain diverse exploitation portfolios rather than concentrating on single product families. The combination of development tools and infrastructure platforms in a single catalog update suggests adversaries are exploiting both the build pipeline and the deployment surface simultaneously.

Federal Civilian Executive Branch agencies must apply patches or implement compensating controls by the deadline. For private sector organizations, the KEV catalog addition serves as a high confidence prioritization signal. Each entry reflects confirmed real world exploitation, not theoretical vulnerability research, making these four CVEs immediate candidates for emergency patching cycles regardless of CVSS score alone.

The January update brings the 2026 KEV catalog additions to six entries in the first three weeks of the year, maintaining the pace established through late 2025 when CISA averaged approximately eight to ten additions per month.