Browse all

Known Exploited Vulnerabilities (CISA KEV) — all

The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.

1,717 results

UrgencyCVEName / productVendorKEV added
High CVE-2026-7273 ↗ Zyxel GS1900 Series Switches — Zyxel GS1900 Series Switches Stack-Based Buffer... Zyxel Sep 21, 2026
High CVE-2025-39682 ↗ Linux Kernel — Linux Kernel Improper Check for Unusual or Exceptional Conditio... Linux Sep 18, 2026
High CVE-2026-53266 ↗ Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability Linux Sep 18, 2026
High CVE-2025-39964 ↗ Linux Kernel — Linux Kernel Race Condition Vulnerability Linux Sep 18, 2026
High CVE-2026-87886 ↗ Acronis Backup — Acronis Backup Incorrect Default Permissions Vulnerability Acronis Sep 16, 2026
High CVE-2026-76460 ↗ Cisco Identity Services Engine — Cisco Identity Services Engine Incorrect Use... Cisco Sep 16, 2026
High CVE-2026-58704 ↗ Google Pixel — Google Pixel Improper Authorization Vulnerability Google Sep 16, 2026
High CVE-2026-76461 ↗ Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerab... Cisco Sep 14, 2026
High CVE-2026-85706 ↗ GitLab Community Edition and Enterprise Edition — GitLab Community Edition and... GitLab Sep 11, 2026
High CVE-2026-42018 ↗ JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability JFrog Sep 11, 2026
High CVE-2026-42016 ↗ JFrog Artifactory — JFrog Artifactory Incorrect Authorization Vulnerability JFrog Sep 11, 2026
High CVE-2026-84869 ↗ ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Privilege Manag... ConnectWise Sep 11, 2026
High CVE-2026-67277 ↗ MikroTik RouterOS — MikroTik RouterOS Missing Authentication for Critical Func... MikroTik Sep 10, 2026
High CVE-2026-86060 ↗ MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Deli... MikroTik Sep 10, 2026
High CVE-2026-20079 ↗ Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC)... Cisco Sep 9, 2026
High CVE-2026-87491 ↗ Google Chromium V8 — Google Chromium V8 Out of Bounds Write Vulnerability Google Sep 9, 2026
High CVE-2025-25249 ↗ Fortinet Multiple Products — Fortinet Multiple Products Heap-based Buffer Over... Fortinet Sep 9, 2026
High CVE-2026-19490 ↗ Citrix NetScaler — Citrix NetScaler Authentication Bypass Using an Alternate P... Citrix Sep 9, 2026
High CVE-2026-85880 ↗ Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability Microsoft Sep 8, 2026
High CVE-2026-86218 ↗ N-able N-central — N-able N-central Static Code Injection Vulnerability N-able Sep 8, 2026
High CVE-2026-81963 ↗ Microsoft Windows — Microsoft Windows Link Following Vulnerability Microsoft Sep 8, 2026
High CVE-2026-75650 ↗ Adobe Commerce and Magento — Adobe Commerce and Magento Improper Neutralizatio... Adobe Sep 8, 2026
High CVE-2026-85046 Explained Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Sep 4, 2026
High CVE-2026-83549 ↗ SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances OS Command Injecti... SonicWall Sep 2, 2026
High CVE-2026-83548 ↗ SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Reques... SonicWall Sep 2, 2026
High CVE-2026-9586 ↗ Sangoma Switchvox — Sangoma Switchvox SQL Injection Vulnerability Sangoma Sep 2, 2026
High CVE-2026-82329 ↗ JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability JFrog Sep 2, 2026
High CVE-2026-49869 ↗ Kestra Kestra OSS — Kestra OSS OS Command Injection Vulnerability Kestra Sep 2, 2026
High CVE-2026-48710 ↗ Kludex Starlette — Kludex Starlette HTTP Request/Response Smuggling Vulnerabil... Kludex Sep 2, 2026
High CVE-2026-59822 ↗ BerriAI LiteLLM — BerriAI LiteLLM Improper Authentication Vulnerability BerriAI Sep 2, 2026
High CVE-2026-81578 Explained PaperCut NG/MF — PaperCut NG/MF Missing Authentication for Critical Function V... PaperCut Aug 31, 2026
High CVE-2026-82078 Explained PaperCut NG/MF — PaperCut NG/MF Unsafe Reflection Vulnerability PaperCut Aug 31, 2026
High CVE-2026-66384 Explained JFrog Artifactory — JFrog Artifactory Improper Limitation of a Pathname to a R... JFrog Aug 27, 2026
High CVE-2026-53362 Explained Linux Kernel — Linux Kernel Unspecified Vulnerability Linux Aug 27, 2026
High CVE-2023-49105 Explained ownCloud ownCloud — ownCloud Improper Authentication Vulnerability ownCloud Aug 27, 2026
High CVE-2019-1068 Explained Microsoft SQL Server — Microsoft SQL Server Remote Code Execution Vulnerabilit... Microsoft Aug 26, 2026
High CVE-2026-8452 ↗ Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScale... Citrix Aug 26, 2026
High CVE-2022-0995 Explained Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability Linux Aug 26, 2026
High CVE-2015-5287 Explained Red Hat Automatic Bug Reporting Tool — Red Hat Automatic Bug Reporting Tool Pr... Red Hat Aug 26, 2026
High CVE-2015-3246 Explained Red Hat Libuser — Red Hat Libuser Race Condition Vulnerability Red Hat Aug 26, 2026
High CVE-2021-23758 Explained Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserializ... Ajax.NET Professional Aug 26, 2026
High CVE-2026-60004 Explained Gitea Gitea — Gitea Code Injection Vulnerability Gitea Aug 25, 2026
High CVE-2026-21962 Explained Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Serv... Oracle Aug 24, 2026
High CVE-2026-73570 Explained Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) OS... Synacor Aug 21, 2026
High CVE-2026-72529 Explained TrueConf Server — TrueConf Server Missing Authentication for Critical Function... TrueConf Aug 20, 2026
High CVE-2026-72530 ↗ TrueConf Server — TrueConf Server Code Injection Vulnerability TrueConf Aug 20, 2026
High CVE-2026-64849 Explained MLflow MLflow — MLflow Server-Side Request Forgery Vulnerability MLflow Aug 19, 2026
High CVE-2026-65400 Explained Apple macOS — Apple macOS Improper Authentication Vulnerability Apple Aug 18, 2026
High CVE-2026-55040 ↗ Microsoft SharePoint — Microsoft SharePoint Weak Authentication Vulnerability Microsoft Aug 18, 2026
Critical CVE-2026-59310 Explained Broadcom VMware vCenter — Broadcom VMware vCenter Path Traversal Vulnerability Broadcom Aug 18, 2026

Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.

About this dataset

This list holds every entry in the Known Exploited Vulnerabilities (KEV) catalog — the vulnerabilities that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed are being exploited in the wild. Tens of thousands of vulnerabilities are disclosed each year; KEV is the short list of those actually seen under attack, meant to drive patching priority.

How to read it

  • Being in KEV is not a theoretical riskTo be listed, a vulnerability needs a CVE identifier, evidence of active exploitation, and a clear remediation path. So every entry is both under attack and fixable. Even when the CVSS score is only moderate, a KEV listing is treated as high priority in practice.
  • The due date is a mandate for federal agencies, not adviceUnder CISA Binding Operational Directive 22-01, U.S. federal civilian executive branch agencies must remediate listed vulnerabilities by the stated due date. Private and non-U.S. organizations are not legally bound, but the date is widely used as a realistic yardstick for how fast to move.
  • The ransomware flag signals blast radiusEntries marked as known to be used in ransomware campaigns have served as an entry point for extortion attacks. Among KEV entries, those carry extra weight because they map directly to business outage.

FAQ

How is KEV different from CVE?
A CVE is the identifier assigned to each disclosed vulnerability; it carries no judgment about risk. KEV is the subset of those CVEs that CISA has confirmed are actively exploited.
Should a high CVSS score outrank a KEV listing?
No. CVSS estimates how severe exploitation would be, not whether it is happening. Common practice is to clear the confirmed-exploited KEV entries first, then work down by CVSS.
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.