CISA KEV Catalog
The Known Exploited Vulnerabilities list from CISA: CVEs with confirmed in-the-wild exploitation, federal remediation due dates, and required actions.
KEV List
1730 total| CVE | Vulnerability | CVSS | EPSS | Added | Due |
|---|---|---|---|---|---|
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | 9.8 | 1.1% | 2026-09-30 | 2026-10-03 |
| CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write Vulnerability | 8.8 | 1.2% | 2026-09-29 | 2026-10-02 |
| CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 9.5 | 1.3% | 2026-09-27 | 2026-09-30 |
| CVE-2026-88771 | Citrix NetScaler Improper Input Validation Vulnerability | 9.5 | 1.1% | 2026-09-27 | 2026-09-30 |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability | 8.1 | 19.8% | 2026-09-25 | 2026-09-28 |
| CVE-2026-67279 | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | 6.9 | 1.0% | 2026-09-25 | 2026-09-28 |
| CVE-2026-65660 | Microsoft SharePoint Code Injection Vulnerability | 8.8 | 2.1% | 2026-09-25 | 2026-09-28 |
| CVE-2026-71362 | Adobe Commerce and Magento Incorrect Authorization Vulnerability | 9.1 | 87.5% | 2026-09-24 | 2026-09-27 |
| CVE-2026-5430 | WSO2 Multiple Products Path Traversal Vulnerability | 10.0 | 0.6% | 2026-09-24 | 2026-09-27 |
| CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | 9.8 | 2.2% | 2026-09-22 | 2026-09-25 |
| CVE-2026-93952 | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | 10.0 | 1.1% | 2026-09-22 | 2026-09-25 |
| CVE-2026-93616 | Check Point Multiple Products Path Traversal Vulnerability | 9.8 | 19.7% | 2026-09-22 | 2026-09-25 |
| CVE-2026-85102 | Check Point Multiple Products Improper Certificate Validation Vulnerability | 9.8 | 7.5% | 2026-09-22 | 2026-09-25 |
| CVE-2026-7273 | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | 8.8 | 2.5% | 2026-09-21 | 2026-09-24 |
| CVE-2026-53266 | Linux Kernel Out-of-Bounds Write Vulnerability | 8.8 | 0.6% | 2026-09-18 | 2026-09-21 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | 7.8 | 1.0% | 2026-09-18 | 2026-09-21 |
| CVE-2025-39682 | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | 9.8 | 2.9% | 2026-09-18 | 2026-09-21 |
| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | 7.8 | 0.2% | 2026-09-16 | 2026-09-19 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | 10.0 | 14.0% | 2026-09-16 | 2026-09-19 |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | 8.8 | 0.6% | 2026-09-16 | 2026-09-19 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | 9.8 | 28.3% | 2026-09-14 | 2026-09-17 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | 10.0 | 93.0% | 2026-09-11 | 2026-09-14 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | 9.9 | 0.9% | 2026-09-11 | 2026-09-14 |
| CVE-2026-42018 | JFrog Artifactory Improper Authentication Vulnerability | 7.5 | 9.8% | 2026-09-11 | 2026-09-25 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | 8.1 | 8.6% | 2026-09-11 | 2026-09-25 |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | 9.2 | 1.8% | 2026-09-10 | 2026-09-13 |
| CVE-2026-67277 | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | 8.8 | 1.6% | 2026-09-10 | 2026-09-13 |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | 8.8 | 3.1% | 2026-09-09 | 2026-09-23 |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | 10.0 | 88.2% | 2026-09-09 | 2026-09-12 |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | 9.3 | 8.0% | 2026-09-09 | 2026-09-12 |
| CVE-2025-25249 | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | 7.4 | 3.9% | 2026-09-09 | 2026-09-12 |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | 10.0 | 12.9% | 2026-09-08 | 2026-09-11 |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | 7.8 | 3.6% | 2026-09-08 | 2026-09-22 |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | 7.8 | 0.4% | 2026-09-08 | 2026-09-22 |
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | 10.0 | 3.9% | 2026-09-08 | 2026-09-11 |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 48.9% | 2026-09-04 | 2026-09-18 |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability | 9.3 | 19.0% | 2026-09-02 | 2026-09-05 |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | 7.8 | 10.8% | 2026-09-02 | 2026-09-05 |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 10.0 | 8.8% | 2026-09-02 | 2026-09-05 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | 9.8 | 14.1% | 2026-09-02 | 2026-09-05 |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | 8.8 | 0.8% | 2026-09-02 | 2026-09-16 |
| CVE-2026-49869 | Kestra OSS OS Command Injection Vulnerability | 10.0 | 2.1% | 2026-09-02 | 2026-09-05 |
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 6.5 | 7.1% | 2026-09-02 | 2026-09-16 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | 9.4 | 61.4% | 2026-08-31 | 2026-09-14 |
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | 8.8 | 85.2% | 2026-08-31 | 2026-09-14 |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 5.3 | 0.7% | 2026-08-27 | 2026-09-10 |
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | 7.8 | 0.7% | 2026-08-27 | 2026-08-30 |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | 9.8 | 42.9% | 2026-08-27 | 2026-08-30 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 8.8 | 1.0% | 2026-08-26 | 2026-08-29 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | 7.8 | 8.8% | 2026-08-26 | 2026-09-09 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 8.1 | 82.6% | 2026-08-26 | 2026-09-09 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | 8.8 | 57.0% | 2026-08-26 | 2026-08-29 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 7.8 | 5.0% | 2026-08-26 | 2026-09-09 |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | 5.1 | 8.8% | 2026-08-26 | 2026-09-09 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | 9.8 | 24.0% | 2026-08-25 | 2026-08-28 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 10.0 | 70.9% | 2026-08-24 | 2026-08-27 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 8.9 | 11.7% | 2026-08-21 | 2026-08-24 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | 9.5 | 1.7% | 2026-08-20 | 2026-09-03 |
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | 9.8 | 1.5% | 2026-08-20 | 2026-08-23 |
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | 9.3 | 9.8% | 2026-08-19 | 2026-09-02 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | 9.8 | 1.7% | 2026-08-18 | 2026-08-21 |
| CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability Ransomware | 9.8 | 2.6% | 2026-08-18 | 2026-08-21 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | 9.1 | 17.5% | 2026-08-18 | 2026-08-21 |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 9.8 | 1.6% | 2026-08-18 | 2026-08-21 |
| CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | 9.4 | 62.5% | 2026-08-17 | 2026-08-20 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | 10.0 | 19.0% | 2026-08-11 | 2026-08-14 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 7.0 | 0.3% | 2026-08-11 | 2026-08-25 |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 8.6 | 1.0% | 2026-08-11 | 2026-08-14 |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | 9.6 | 77.4% | 2026-08-07 | 2026-08-10 |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability Ransomware | 9.8 | 89.6% | 2026-08-05 | 2026-08-08 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | 9.8 | 28.7% | 2026-08-04 | 2026-08-07 |
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 7.5 | 6.6% | 2026-08-04 | 2026-08-07 |
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 8.2 | 7.9% | 2026-08-04 | 2026-08-07 |
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 8.2 | 14.6% | 2026-08-03 | 2026-08-06 |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Ransomware | 5.3 | 35.1% | 2026-07-29 | 2026-08-01 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 10.0 | 1.0% | 2026-07-27 | 2026-07-30 |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 5.3 | 29.6% | 2026-07-27 | 2026-08-10 |
| CVE-2026-50522 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | 3.0% | 2026-07-22 | 2026-07-25 |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | 9.3 | 78.0% | 2026-07-22 | 2026-07-25 |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | 9.8 | 10.1% | 2026-07-21 | 2026-07-24 |
| CVE-2026-60137 | WordPress Core SQL Injection Vulnerability | 9.1 | 5.9% | 2026-07-21 | 2026-08-04 |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 9.8 | 63.8% | 2026-07-21 | 2026-07-24 |
| CVE-2021-27137 | DD-WRT Stack-Based Buffer Overflow Vulnerability | 8.1 | 4.0% | 2026-07-21 | 2026-07-24 |
| CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | 15.9% | 2026-07-16 | 2026-07-19 |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.1 | 47.4% | 2026-07-16 | 2026-07-19 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.1 | 76.1% | 2026-07-16 | 2026-07-19 |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | 9.8 | 0.8% | 2026-07-15 | 2026-07-18 |
| CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 7.5 | 1.3% | 2026-07-15 | 2026-07-29 |
| CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 5.3 | 1.0% | 2026-07-14 | 2026-07-17 |
| CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 7.8 | 0.3% | 2026-07-14 | 2026-07-28 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability Ransomware | 7.2 | 11.8% | 2026-07-14 | 2026-07-17 |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability Ransomware | 10.0 | 6.8% | 2026-07-14 | 2026-07-17 |
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | 8.1 | 33.9% | 2026-07-13 | 2026-07-16 |
| CVE-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 10.0 | 14.9% | 2026-07-10 | 2026-07-13 |
| CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 10.0 | 20.1% | 2026-07-10 | 2026-07-13 |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | 10.0 | 30.9% | 2026-07-07 | 2026-07-10 |
| CVE-2026-55255 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | 8.4 | 0.9% | 2026-07-07 | 2026-07-10 |
| CVE-2026-48908 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 10.0 | 88.5% | 2026-07-07 | 2026-07-10 |
| CVE-2026-48282 | Adobe ColdFusion Path Traversal Vulnerability | 10.0 | 42.4% | 2026-07-07 | 2026-07-10 |
| CVE-2026-45659 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Ransomware | 8.8 | 2.7% | 2026-07-01 | 2026-07-04 |
Frequently Asked Questions
What is the CISA KEV catalog?→
The Known Exploited Vulnerabilities (KEV) catalog is CISA's list of CVEs with confirmed exploitation in the wild. Each entry includes the affected product, a required remediation action, and a due date.
What is the difference between KEV and NVD?→
NVD scores and enriches CVE records with severity ratings and affected-product data. KEV is a much smaller list: it only contains CVEs where exploitation is confirmed. NVD tells you how severe a flaw is on paper; KEV tells you it is being used in attacks.
How do I check if a CVE is exploited?→
Every CVE on this page has confirmed exploitation per CISA. Record pages on this site also carry a KEV flag with the due date. For CVEs not in KEV, the EPSS score on each record estimates the probability of exploitation in the next 30 days.
What does the remediation due date mean?→
The due date is the remediation deadline CISA sets for US federal agencies under Binding Operational Directive 26-04 (which superseded BOD 22-01 in June 2026). Outside government it works as a priority signal: entries with near or past due dates are the most urgent to remediate.
How often is the KEV catalog updated?→
CISA adds entries as exploitation is confirmed, typically several times a month. This page syncs daily against the official catalog feed.
Data: CISA Known Exploited Vulnerabilities catalog (CC0), EPSS by FIRST (first.org/epss). This site is not endorsed or certified by CISA or FIRST.