CISA KEV Catalog
The Known Exploited Vulnerabilities list from CISA: CVEs with confirmed in-the-wild exploitation, federal remediation due dates, and required actions.
KEV in Numbers
- As of October 10, 2026, the CISA Known Exploited Vulnerabilities (KEV) catalog lists 1,739 CVEs with reliable evidence of active exploitation in the wild.
- CISA added 303 vulnerabilities to the KEV catalog in the 12 months to October 10, 2026, and 255 so far in 2026.
- Since June 10, 2026, 81% of new CISA KEV entries (99 of 122) have had a remediation due date 3 days or less after they were added, compared with 3% of entries added in 2025.
KEV List
1739 total| CVE | Vulnerability | CVSS | EPSS | Added | Due |
|---|
No records match the selected filters.
| CVE | Vulnerability | CVSS | EPSS | Added | Due |
|---|---|---|---|---|---|
| CVE-2023-22894 | Strapi Cleartext Storage of Sensitive Information Vulnerability | 7.2 | 3.4% | 2026-10-08 | 2026-10-11 |
| CVE-2021-3199 | ONLYOFFICE Docs Server Path Traversal Vulnerability | 9.8 | 14.5% | 2026-10-08 | 2026-10-11 |
| CVE-2016-3081 | Apache Struts Command Injection Vulnerability | 8.1 | 94.5% | 2026-10-08 | 2026-10-11 |
| CVE-2015-5477 | ISC BIND Data Processing Errors Vulnerability | 7.5 | 91.8% | 2026-10-08 | 2026-10-11 |
| CVE-2015-3306 | ProFTPD Improper Access Control Vulnerability | 10.0 | 98.0% | 2026-10-08 | 2026-10-11 |
| CVE-2026-88779 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 8.7 | 0.6% | 2026-10-04 | 2026-10-07 |
| CVE-2026-102490 | Zammad GmbH Zammad Improper Privilege Management Vulnerability | 9.4 | 0.5% | 2026-10-02 | 2026-10-05 |
| CVE-2026-102489 | Zammad GmbH Zammad Session Fixation Vulnerability | 9.4 | 1.3% | 2026-10-02 | 2026-10-05 |
| CVE-2026-104286 | Fortinet FortiMail Path Traversal Vulnerability | 9.8 | 2.2% | 2026-10-01 | 2026-10-04 |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | 9.8 | 1.8% | 2026-09-30 | 2026-10-03 |
| CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write Vulnerability | 8.8 | 1.2% | 2026-09-29 | 2026-10-13 |
| CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 9.5 | 1.3% | 2026-09-27 | 2026-09-30 |
| CVE-2026-88771 | Citrix NetScaler Improper Input Validation Vulnerability | 9.5 | 1.1% | 2026-09-27 | 2026-09-30 |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability | 8.1 | 40.0% | 2026-09-25 | 2026-09-28 |
| CVE-2026-67279 | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | 6.9 | 1.0% | 2026-09-25 | 2026-09-28 |
| CVE-2026-65660 | Microsoft SharePoint Code Injection Vulnerability | 8.8 | 2.1% | 2026-09-25 | 2026-09-28 |
| CVE-2026-71362 | Adobe Commerce and Magento Incorrect Authorization Vulnerability | 9.1 | 87.5% | 2026-09-24 | 2026-09-27 |
| CVE-2026-5430 | WSO2 Multiple Products Path Traversal Vulnerability | 10.0 | 0.6% | 2026-09-24 | 2026-09-27 |
| CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | 9.8 | 2.2% | 2026-09-22 | 2026-09-25 |
| CVE-2026-93952 | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | 10.0 | 1.1% | 2026-09-22 | 2026-09-25 |
| CVE-2026-93616 | Check Point Multiple Products Path Traversal Vulnerability | 9.8 | 19.7% | 2026-09-22 | 2026-09-25 |
| CVE-2026-85102 | Check Point Multiple Products Improper Certificate Validation Vulnerability | 9.8 | 7.5% | 2026-09-22 | 2026-09-25 |
| CVE-2026-7273 | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | 8.8 | 2.5% | 2026-09-21 | 2026-09-24 |
| CVE-2026-53266 | Linux Kernel Out-of-Bounds Write Vulnerability | 8.8 | 0.8% | 2026-09-18 | 2026-09-21 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | 7.8 | 1.3% | 2026-09-18 | 2026-09-21 |
| CVE-2025-39682 | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | 9.8 | 2.9% | 2026-09-18 | 2026-09-21 |
| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | 7.8 | 0.2% | 2026-09-16 | 2026-09-19 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | 10.0 | 14.0% | 2026-09-16 | 2026-09-19 |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | 8.8 | 0.6% | 2026-09-16 | 2026-09-19 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | 9.8 | 28.3% | 2026-09-14 | 2026-09-17 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | 10.0 | 93.0% | 2026-09-11 | 2026-09-14 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | 9.9 | 0.9% | 2026-09-11 | 2026-09-14 |
| CVE-2026-42018 | JFrog Artifactory Improper Authentication Vulnerability | 7.5 | 9.8% | 2026-09-11 | 2026-09-25 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | 8.1 | 8.6% | 2026-09-11 | 2026-09-25 |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | 9.2 | 6.4% | 2026-09-10 | 2026-09-13 |
| CVE-2026-67277 | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | 8.8 | 1.6% | 2026-09-10 | 2026-09-13 |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | 8.8 | 3.1% | 2026-09-09 | 2026-09-23 |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | 10.0 | 88.2% | 2026-09-09 | 2026-09-12 |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | 9.3 | 23.2% | 2026-09-09 | 2026-09-12 |
| CVE-2025-25249 | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | 7.4 | 3.8% | 2026-09-09 | 2026-09-12 |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | 10.0 | 14.5% | 2026-09-08 | 2026-09-11 |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | 7.8 | 3.6% | 2026-09-08 | 2026-09-22 |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | 7.8 | 0.4% | 2026-09-08 | 2026-09-22 |
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | 10.0 | 3.9% | 2026-09-08 | 2026-09-11 |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 48.9% | 2026-09-04 | 2026-09-18 |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability | 9.3 | 19.0% | 2026-09-02 | 2026-09-05 |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | 7.8 | 10.8% | 2026-09-02 | 2026-09-05 |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 10.0 | 8.8% | 2026-09-02 | 2026-09-05 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | 9.8 | 14.1% | 2026-09-02 | 2026-09-05 |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | 8.8 | 0.8% | 2026-09-02 | 2026-09-16 |
| CVE-2026-49869 | Kestra OSS OS Command Injection Vulnerability | 10.0 | 2.1% | 2026-09-02 | 2026-09-05 |
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 6.5 | 7.1% | 2026-09-02 | 2026-09-16 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | 9.4 | 63.5% | 2026-08-31 | 2026-09-14 |
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | 8.8 | 85.6% | 2026-08-31 | 2026-09-14 |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 5.3 | 0.7% | 2026-08-27 | 2026-09-10 |
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | 7.8 | 0.7% | 2026-08-27 | 2026-08-30 |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | 9.8 | 42.9% | 2026-08-27 | 2026-08-30 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 8.8 | 1.0% | 2026-08-26 | 2026-08-29 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | 7.8 | 8.8% | 2026-08-26 | 2026-08-29 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 8.1 | 82.6% | 2026-08-26 | 2026-09-09 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | 8.8 | 57.3% | 2026-08-26 | 2026-08-29 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 7.8 | 5.0% | 2026-08-26 | 2026-09-09 |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | 7.4 | 8.4% | 2026-08-26 | 2026-09-09 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | 9.8 | 24.0% | 2026-08-25 | 2026-08-28 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 10.0 | 73.2% | 2026-08-24 | 2026-08-27 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 8.9 | 71.7% | 2026-08-21 | 2026-08-24 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | 9.5 | 1.7% | 2026-08-20 | 2026-09-03 |
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | 9.8 | 1.5% | 2026-08-20 | 2026-08-23 |
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | 9.3 | 9.8% | 2026-08-19 | 2026-09-02 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | 9.8 | 1.7% | 2026-08-18 | 2026-08-21 |
| CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability Ransomware | 9.8 | 2.6% | 2026-08-18 | 2026-08-21 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | 9.1 | 69.5% | 2026-08-18 | 2026-08-21 |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 9.8 | 1.6% | 2026-08-18 | 2026-08-21 |
| CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | 9.4 | 62.5% | 2026-08-17 | 2026-08-20 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | 10.0 | 19.0% | 2026-08-11 | 2026-08-14 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 7.0 | 0.3% | 2026-08-11 | 2026-08-25 |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 8.6 | 1.0% | 2026-08-11 | 2026-08-14 |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | 9.6 | 77.4% | 2026-08-07 | 2026-08-10 |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability Ransomware | 9.8 | 89.6% | 2026-08-05 | 2026-08-08 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | 9.8 | 28.7% | 2026-08-04 | 2026-08-07 |
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 7.5 | 6.6% | 2026-08-04 | 2026-08-07 |
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 8.2 | 7.9% | 2026-08-04 | 2026-08-07 |
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 8.2 | 14.6% | 2026-08-03 | 2026-08-06 |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Ransomware | 5.3 | 35.1% | 2026-07-29 | 2026-08-01 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 10.0 | 1.0% | 2026-07-27 | 2026-07-30 |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 5.3 | 29.5% | 2026-07-27 | 2026-08-10 |
| CVE-2026-50522 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | 3.0% | 2026-07-22 | 2026-07-25 |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | 9.3 | 78.0% | 2026-07-22 | 2026-07-25 |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | 9.8 | 10.6% | 2026-07-21 | 2026-07-24 |
| CVE-2026-60137 | WordPress Core SQL Injection Vulnerability | 5.9 | 5.3% | 2026-07-21 | 2026-08-04 |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 9.8 | 63.0% | 2026-07-21 | 2026-07-24 |
| CVE-2021-27137 | DD-WRT Stack-Based Buffer Overflow Vulnerability | 8.1 | 4.0% | 2026-07-21 | 2026-07-24 |
| CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | 15.9% | 2026-07-16 | 2026-07-19 |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.1 | 47.4% | 2026-07-16 | 2026-07-19 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.1 | 76.1% | 2026-07-16 | 2026-07-19 |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | 9.8 | 0.8% | 2026-07-15 | 2026-07-18 |
| CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 7.5 | 1.3% | 2026-07-15 | 2026-07-29 |
| CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 5.3 | 1.0% | 2026-07-14 | 2026-07-17 |
| CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 7.8 | 0.3% | 2026-07-14 | 2026-07-28 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability Ransomware | 7.2 | 11.8% | 2026-07-14 | 2026-07-17 |
Frequently Asked Questions
What is the CISA KEV catalog?→
The Known Exploited Vulnerabilities (KEV) catalog is CISA's list of CVEs with confirmed exploitation in the wild. Each entry includes the affected product, a required remediation action, and a due date.
What is the difference between KEV and NVD?→
NVD, run by NIST, enriches CVE records within its scope of coverage with CVSS scores, CWE mappings, and affected-product (CPE) data. KEV is a much smaller list: it only contains CVEs where exploitation is confirmed. NVD tells you how severe a flaw is on paper; KEV tells you it is being used in attacks.
How do I check if a CVE is exploited?→
Every CVE on this page has confirmed exploitation per CISA. Record pages on this site also carry a KEV flag with the due date. For CVEs not in KEV, the EPSS score on each record estimates the probability of exploitation in the next 30 days.
What does the remediation due date mean?→
The due date is the remediation deadline CISA lists for US federal civilian agencies. Since June 10, 2026 these deadlines fall under Binding Operational Directive 26-04, which superseded BOD 22-01 and ties remediation timelines to risk factors such as whether the affected asset is publicly exposed. Outside government it works as a priority signal: entries with near or past due dates are the most urgent to remediate.
How often is the KEV catalog updated?→
CISA adds a vulnerability once it has an assigned CVE ID, reliable evidence of active exploitation in the wild, and a clear remediation action. This page syncs daily against the official catalog feed.
Data: CISA Known Exploited Vulnerabilities catalog (CC0), EPSS by FIRST (first.org/epss). This site is not endorsed or certified by CISA or FIRST.