CISA Adds Microsoft Office and SharePoint Vulnerabilities to Known Exploited Vulnerabilities Catalog
The **Cybersecurity and Infrastructure Security Agency (CISA)** has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding two **Microsoft** vulnerabilities. These vulnerabilities, affecting **Microsoft Office** and **SharePoint Server**, are known to be actively exploited in the wild and pose a significant risk.
The **Cybersecurity and Infrastructure Security Agency (CISA)** has added two new vulnerabilities to its [Known Exploited Vulnerabilities (KEV) Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog), based on evidence of active exploitation.
* [**CVE-2009-0238**](https://www.cve.org/CVERecord?id=CVE-2009-0238) **Microsoft Office** Remote Code Execution Vulnerability
* [**CVE-2026-32201**](https://www.cve.org/CVERecord?id=CVE-2026-32201) **Microsoft SharePoint Server** Improper Input Validation Vulnerability
### Risk to Federal Enterprises
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
### Binding Operational Directive 22-01
[Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities](https://www.cisa.gov/binding-operational-directive-22-01) established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the [BOD 22-01 Fact Sheet ](https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf)for more information.
### Recommendation for All Organizations
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of [KEV Catalog vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the [specified criteria](https://www.cisa.gov/known-exploited-vulnerabilities).