TL;DR
CISA has added two new vulnerabilities, CVE-2025-11953 and CVE-2026-24423, to the Known Exploited Vulnerabilities (KEV) Catalog. These affect React Native Community CLI and SmarterTools SmarterMail.
What happened
['CISA added two new vulnerabilities to its KEV catalog', 'CVE-2025-11953: OS Command Injection in React Native Community CLI', 'CVE-2026-24423: Missing Authentication for Critical Function in SmarterTools SmarterMail']
Why it matters for ops
['These vulnerabilities are actively exploited by malicious actors', 'They pose significant risks to federal enterprise networks', 'CISA requires FCEB agencies to remediate these by due dates']
Mitigation
- Update to the latest patch versions
- Implement strict least privilege access controls
- Regularly review and remediate KEV Catalog entries
Action items
- Apply relevant patches immediately
- Conduct a risk assessment of current systems
- Educate staff on recognizing and responding to exploits
Detection IOCs
- Look for unauthorized access attempts in logs
- Monitor OS command execution patterns
- Check for unusual authentication failures or bypasses