Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,717 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2026-7273 ↗ | Zyxel GS1900 Series Switches — Zyxel GS1900 Series Switches Stack-Based Buffer... | Zyxel | Sep 21, 2026 |
| High | CVE-2025-39682 ↗ | Linux Kernel — Linux Kernel Improper Check for Unusual or Exceptional Conditio... | Linux | Sep 18, 2026 |
| High | CVE-2026-53266 ↗ | Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability | Linux | Sep 18, 2026 |
| High | CVE-2025-39964 ↗ | Linux Kernel — Linux Kernel Race Condition Vulnerability | Linux | Sep 18, 2026 |
| High | CVE-2026-87886 ↗ | Acronis Backup — Acronis Backup Incorrect Default Permissions Vulnerability | Acronis | Sep 16, 2026 |
| High | CVE-2026-76460 ↗ | Cisco Identity Services Engine — Cisco Identity Services Engine Incorrect Use... | Cisco | Sep 16, 2026 |
| High | CVE-2026-58704 ↗ | Google Pixel — Google Pixel Improper Authorization Vulnerability | Sep 16, 2026 | |
| High | CVE-2026-76461 ↗ | Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerab... | Cisco | Sep 14, 2026 |
| High | CVE-2026-85706 ↗ | GitLab Community Edition and Enterprise Edition — GitLab Community Edition and... | GitLab | Sep 11, 2026 |
| High | CVE-2026-42018 ↗ | JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability | JFrog | Sep 11, 2026 |
| High | CVE-2026-42016 ↗ | JFrog Artifactory — JFrog Artifactory Incorrect Authorization Vulnerability | JFrog | Sep 11, 2026 |
| High | CVE-2026-84869 ↗ | ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Privilege Manag... | ConnectWise | Sep 11, 2026 |
| High | CVE-2026-67277 ↗ | MikroTik RouterOS — MikroTik RouterOS Missing Authentication for Critical Func... | MikroTik | Sep 10, 2026 |
| High | CVE-2026-86060 ↗ | MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Deli... | MikroTik | Sep 10, 2026 |
| High | CVE-2026-20079 ↗ | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC)... | Cisco | Sep 9, 2026 |
| High | CVE-2026-87491 ↗ | Google Chromium V8 — Google Chromium V8 Out of Bounds Write Vulnerability | Sep 9, 2026 | |
| High | CVE-2025-25249 ↗ | Fortinet Multiple Products — Fortinet Multiple Products Heap-based Buffer Over... | Fortinet | Sep 9, 2026 |
| High | CVE-2026-19490 ↗ | Citrix NetScaler — Citrix NetScaler Authentication Bypass Using an Alternate P... | Citrix | Sep 9, 2026 |
| High | CVE-2026-85880 ↗ | Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Microsoft | Sep 8, 2026 |
| High | CVE-2026-86218 ↗ | N-able N-central — N-able N-central Static Code Injection Vulnerability | N-able | Sep 8, 2026 |
| High | CVE-2026-81963 ↗ | Microsoft Windows — Microsoft Windows Link Following Vulnerability | Microsoft | Sep 8, 2026 |
| High | CVE-2026-75650 ↗ | Adobe Commerce and Magento — Adobe Commerce and Magento Improper Neutralizatio... | Adobe | Sep 8, 2026 |
| High | CVE-2026-85046 Explained | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | Sep 4, 2026 | |
| High | CVE-2026-83549 ↗ | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances OS Command Injecti... | SonicWall | Sep 2, 2026 |
| High | CVE-2026-83548 ↗ | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Reques... | SonicWall | Sep 2, 2026 |
| High | CVE-2026-9586 ↗ | Sangoma Switchvox — Sangoma Switchvox SQL Injection Vulnerability | Sangoma | Sep 2, 2026 |
| High | CVE-2026-82329 ↗ | JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability | JFrog | Sep 2, 2026 |
| High | CVE-2026-49869 ↗ | Kestra Kestra OSS — Kestra OSS OS Command Injection Vulnerability | Kestra | Sep 2, 2026 |
| High | CVE-2026-48710 ↗ | Kludex Starlette — Kludex Starlette HTTP Request/Response Smuggling Vulnerabil... | Kludex | Sep 2, 2026 |
| High | CVE-2026-59822 ↗ | BerriAI LiteLLM — BerriAI LiteLLM Improper Authentication Vulnerability | BerriAI | Sep 2, 2026 |
| High | CVE-2026-81578 Explained | PaperCut NG/MF — PaperCut NG/MF Missing Authentication for Critical Function V... | PaperCut | Aug 31, 2026 |
| High | CVE-2026-82078 Explained | PaperCut NG/MF — PaperCut NG/MF Unsafe Reflection Vulnerability | PaperCut | Aug 31, 2026 |
| High | CVE-2026-66384 Explained | JFrog Artifactory — JFrog Artifactory Improper Limitation of a Pathname to a R... | JFrog | Aug 27, 2026 |
| High | CVE-2026-53362 Explained | Linux Kernel — Linux Kernel Unspecified Vulnerability | Linux | Aug 27, 2026 |
| High | CVE-2023-49105 Explained | ownCloud ownCloud — ownCloud Improper Authentication Vulnerability | ownCloud | Aug 27, 2026 |
| High | CVE-2019-1068 Explained | Microsoft SQL Server — Microsoft SQL Server Remote Code Execution Vulnerabilit... | Microsoft | Aug 26, 2026 |
| High | CVE-2026-8452 ↗ | Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScale... | Citrix | Aug 26, 2026 |
| High | CVE-2022-0995 Explained | Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability | Linux | Aug 26, 2026 |
| High | CVE-2015-5287 Explained | Red Hat Automatic Bug Reporting Tool — Red Hat Automatic Bug Reporting Tool Pr... | Red Hat | Aug 26, 2026 |
| High | CVE-2015-3246 Explained | Red Hat Libuser — Red Hat Libuser Race Condition Vulnerability | Red Hat | Aug 26, 2026 |
| High | CVE-2021-23758 Explained | Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserializ... | Ajax.NET Professional | Aug 26, 2026 |
| High | CVE-2026-60004 Explained | Gitea Gitea — Gitea Code Injection Vulnerability | Gitea | Aug 25, 2026 |
| High | CVE-2026-21962 Explained | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Serv... | Oracle | Aug 24, 2026 |
| High | CVE-2026-73570 Explained | Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) OS... | Synacor | Aug 21, 2026 |
| High | CVE-2026-72529 Explained | TrueConf Server — TrueConf Server Missing Authentication for Critical Function... | TrueConf | Aug 20, 2026 |
| High | CVE-2026-72530 ↗ | TrueConf Server — TrueConf Server Code Injection Vulnerability | TrueConf | Aug 20, 2026 |
| High | CVE-2026-64849 Explained | MLflow MLflow — MLflow Server-Side Request Forgery Vulnerability | MLflow | Aug 19, 2026 |
| High | CVE-2026-65400 Explained | Apple macOS — Apple macOS Improper Authentication Vulnerability | Apple | Aug 18, 2026 |
| High | CVE-2026-55040 ↗ | Microsoft SharePoint — Microsoft SharePoint Weak Authentication Vulnerability | Microsoft | Aug 18, 2026 |
| Critical | CVE-2026-59310 Explained | Broadcom VMware vCenter — Broadcom VMware vCenter Path Traversal Vulnerability | Broadcom | Aug 18, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.
About this dataset
This list holds every entry in the Known Exploited Vulnerabilities (KEV) catalog — the vulnerabilities that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed are being exploited in the wild. Tens of thousands of vulnerabilities are disclosed each year; KEV is the short list of those actually seen under attack, meant to drive patching priority.
How to read it
- Being in KEV is not a theoretical riskTo be listed, a vulnerability needs a CVE identifier, evidence of active exploitation, and a clear remediation path. So every entry is both under attack and fixable. Even when the CVSS score is only moderate, a KEV listing is treated as high priority in practice.
- The due date is a mandate for federal agencies, not adviceUnder CISA Binding Operational Directive 22-01, U.S. federal civilian executive branch agencies must remediate listed vulnerabilities by the stated due date. Private and non-U.S. organizations are not legally bound, but the date is widely used as a realistic yardstick for how fast to move.
- The ransomware flag signals blast radiusEntries marked as known to be used in ransomware campaigns have served as an entry point for extortion attacks. Among KEV entries, those carry extra weight because they map directly to business outage.