cisaregulatorNewsThe Broadside1 min read

CISA adds Cisco IOS CVE-2008-4128 to KEV

Federal agencies get a binding remediation priority, but CISA’s alert leaves the exact BOD 26-04 deadline unstated.


TL;DR

CISA added CVE-2008-4128, a Cisco IOS cross-site request forgery vulnerability, to the Known Exploited Vulnerabilities Catalog after evidence of active exploitation. Federal Civilian Executive Branch agencies must prioritize remediation under Binding Operational Directive 26-04 for qualifying publicly exposed assets. State CISOs and contractors servicing federal networks should treat the listing as a practical audit and remediation trigger.

CISA’s update is a routine KEV Catalog entry with one operational point: CVE-2008-4128 is now on the federal priority list because CISA says it has evidence of active exploitation. Binding Operational Directive 26-04 applies to Federal Civilian Executive Branch agencies and requires risk-based prioritization for KEV-listed vulnerabilities on publicly exposed assets that can give an attacker total control after exploitation. The alert does not state the specific remediation deadline for this CVE, so agency teams and contractors supporting federal networks should check the BOD 26-04 timeline, confirm exposure, patch where required, and assess whether the system was compromised before remediation.


Published ·Deep Fathom