Federal agencies must patch Daemon Tools Lite, TanStack, and Nx Console flaws by assigned deadlines under BOD 22-01.
- CISA added CVE-2026-8398, CVE-2026-45321, and CVE-2026-48027 to its Known Exploited Vulnerabilities catalog
- Federal agencies must remediate these vulnerabilities by assigned due dates under Binding Operational Directive 22-01
- The vulnerabilities affect Daemon Tools Lite, TanStack, and Nx Console products with evidence of active exploitation
The US Cybersecurity and Infrastructure Security Agency has added three vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence that attackers are actively exploiting the flaws.
The newly catalogued vulnerabilities are CVE-2026-8398 in Daemon Tools Lite, described as an embedded malicious code vulnerability, CVE-2026-45321 in TanStack listed as an unspecified vulnerability, and CVE-2026-48027 in Nx Console, also described as an embedded malicious code vulnerability.
Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies must remediate these vulnerabilities by assigned due dates to protect federal networks against active threats.
CISA established the KEV catalog as a living list of Common Vulnerabilities and Exposures that carry significant risk to the federal enterprise. The directive requires federal agencies to prioritise patching these vulnerabilities over other security updates because of evidence of active exploitation.
While BOD 22-01 applies only to federal civilian agencies, CISA strongly urges all organisations to reduce their exposure to cyberattacks by prioritising timely remediation of KEV catalog vulnerabilities as part of their vulnerability management practice.
The agency noted that these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. CISA will continue to add vulnerabilities to the catalog that meet specified criteria for evidence of active exploitation.
Why It Matters
The addition of these vulnerabilities to the KEV catalog signals that attackers are actively exploiting these flaws in the wild, creating immediate risk for organisations using the affected software. For CISOs, this represents a clear signal to prioritise these patches over routine vulnerability management activities, particularly given the embedded malicious code nature of two of the three vulnerabilities.
While the directive only mandates federal agency compliance, boards and executives increasingly expect private sector organisations to follow federal cybersecurity guidance. CISOs should prepare to explain their organisation’s patch timeline and risk exposure for these specific vulnerabilities.
What To Do Now
- Check if your organisation uses Daemon Tools Lite, TanStack, or Nx Console products and prioritise patching if present
- Review your vulnerability management process to ensure KEV catalog additions trigger immediate assessment and remediation workflows
- Monitor CISA’s KEV catalog regularly as the agency continues to add vulnerabilities that meet criteria for active exploitation
