CISA added four vulnerabilities to its KEV catalog on January 22, 2026, confirming active exploitation in Versa Concerto, Zimbra, Vite, and Prettier tools. Federal deadline is February 12; enterprises urged to patch immediately against auth bypass, file inclusion, and supply-chain malware.