Skip to content

Data collected

CVEs Live

Added to CISA KEV, 24 Aug 2026 to 30 Aug 2026

11 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

  1. CVE-2021-23758Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Ajax.NET Professional · Ajax.NET Professional

    Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    82.6%99.7th pct

    KEV dates

    added due
  2. CVE-2026-21962Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    70.9%99.4th pct

    KEV dates

    added due
  3. CVE-2019-1068Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SQL Server

    Microsoft SQL Server Remote Code Execution Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    57.0%99.0th pct

    KEV dates

    added due
  4. CVE-2023-49105Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    ownCloud · ownCloud

    ownCloud Improper Authentication Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    42.9%99th pct

    KEV dates

    added due
  5. CVE-2026-60004Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Gitea · Gitea

    Gitea Code Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · mitre.org

    Attack probability (EPSS)

    24.0%98th pct

    KEV dates

    added due
  6. CVE-2022-0995Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    8.79%95th pct

    KEV dates

    added due
  7. CVE-2015-3246Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Red Hat · Libuser

    Red Hat Libuser Race Condition Vulnerability

    Severity

    7.4HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    8.43%95th pct

    KEV dates

    added due
  8. CVE-2015-5287Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Red Hat · Automatic Bug Reporting Tool

    Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    4.96%92th pct

    KEV dates

    added due
  9. CVE-2026-8452Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler ADC and NetScaler Gateway

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.01%62th pct

    KEV dates

    added due
  10. CVE-2026-53362Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Unspecified Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    0.71%52th pct

    KEV dates

    added due
  11. CVE-2026-66384Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    Severity

    5.3MEDIUMCVSS 3.1 · jfrog.com

    Attack probability (EPSS)

    0.66%50th pct

    KEV dates

    added due

All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.

The week in numbers

9 vendors had products added: Linux (2), Red Hat (2), Ajax.NET Professional (1), Oracle (1), Microsoft (1), ownCloud (1), Gitea (1), Citrix (1), JFrog (1). CISA marks none of the 11 as known to be used in ransomware campaigns.

Due dates in this batch run from 27 Aug 2026 to 10 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.

Other weeks

Questions

How many vulnerabilities were added to CISA KEV in the week of 24 Aug 2026?

11, between 24 Aug 2026 and 30 Aug 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.

Why do additions come in batches?

CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.

How is the week defined?

By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.

Related sections