Skip to content

Data collected

CVEs Live

CISA KEV catalog, searchable

Every vulnerability CISA lists as exploited in the wild, with the EPSS probability and the published CVSS beside each one. Newest additions first; switch to Risk to put ransomware-linked and high-EPSS entries on top.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

1,733
flaws with confirmed attacks
361
used by ransomware
39
added in 30 days

203 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-102489Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Zammad GmbH · Zammad

    Zammad GmbH Zammad Session Fixation Vulnerability

    Severity

    9.4CRITICALCVSS 4.0 · divd.nl

    Attack probability (EPSS)

    0.58%46th pct

    KEV dates

    added due
  2. CVE-2026-102490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Zammad GmbH · Zammad

    Zammad GmbH Zammad Improper Privilege Management Vulnerability

    Severity

    9.4CRITICALCVSS 4.0 · divd.nl

    Attack probability (EPSS)

    0.26%16th pct

    KEV dates

    added due
  3. CVE-2026-104286Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Fortinet · FortiMail

    Fortinet FortiMail Path Traversal Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · fortinet.com

    Attack probability (EPSS)

    1.78%77th pct

    KEV dates

    added due
  4. CVE-2026-76504Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    1.57%75th pct

    KEV dates

    added due
  5. CVE-2026-86950Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Apple · Multiple Products

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    1.24%68th pct

    KEV dates

    added due
  6. CVE-2026-88772Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Severity

    9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.30%69th pct

    KEV dates

    added due
  7. CVE-2026-88771Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Improper Input Validation Vulnerability

    Severity

    9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.06%63th pct

    KEV dates

    added due
  8. CVE-2026-87902Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    WordPress · Core

    WordPress Core Remote File Inclusion Vulnerability

    Severity

    8.1HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    45.5%99th pct

    KEV dates

    added due
  9. CVE-2026-65660Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint

    Microsoft SharePoint Code Injection Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    2.10%81th pct

    KEV dates

    added due
  10. CVE-2026-67279Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    MikroTik · RouterOS

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    Severity

    6.9MEDIUMCVSS 4.0 · cert.pl

    Attack probability (EPSS)

    1.03%62th pct

    KEV dates

    added due
  11. CVE-2026-71362Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Severity

    9.1CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    87.5%99.8th pct

    KEV dates

    added due
  12. CVE-2026-5430Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    WSO2 · Multiple Products

    WSO2 Multiple Products Path Traversal Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · ed10eef1-636d-4fbe-9993-6890dfa878f8

    Attack probability (EPSS)

    0.59%46th pct

    KEV dates

    added due
  13. CVE-2026-93616Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Check Point · Multiple Products

    Check Point Multiple Products Path Traversal Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · checkpoint.com

    Attack probability (EPSS)

    19.7%97th pct

    KEV dates

    added due
  14. CVE-2026-85102Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Check Point · Multiple Products

    Check Point Multiple Products Improper Certificate Validation Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · checkpoint.com

    Attack probability (EPSS)

    7.55%94th pct

    KEV dates

    added due
  15. CVE-2026-94127Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    F5 · BIG-IP APM

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · f5.com

    Attack probability (EPSS)

    2.23%82th pct

    KEV dates

    added due
  16. CVE-2026-93952Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Arista · VeloCloud Orchestrator

    Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

    Severity

    9.5CRITICALCVSS 4.0 · arista.com

    Attack probability (EPSS)

    1.06%63th pct

    KEV dates

    added due
  17. CVE-2026-7273Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Zyxel · GS1900 Series Switches

    Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · zyxel.com.tw

    Attack probability (EPSS)

    2.50%84th pct

    KEV dates

    added due
  18. CVE-2025-39682Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    2.88%86th pct

    KEV dates

    added due
  19. CVE-2025-39964Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Race Condition Vulnerability

    Severity

    5.5MEDIUMCVSS 3.1 · NVD

    Attack probability (EPSS)

    1.00%61th pct

    KEV dates

    added due
  20. CVE-2026-53266Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Linux · Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Attack probability (EPSS)

    0.83%56th pct

    KEV dates

    added due
  21. CVE-2026-76460Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Identity Services Engine

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    14.0%96th pct

    KEV dates

    added due
  22. CVE-2026-58704Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Pixel

    Google Pixel Improper Authorization Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    0.59%46th pct

    KEV dates

    added due
  23. CVE-2026-87886Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Acronis · Backup

    Acronis Backup Incorrect Default Permissions Vulnerability

    Severity

    7.8HIGHCVSS 3.0 · acronis.com

    Attack probability (EPSS)

    0.23%13th pct

    KEV dates

    added due
  24. CVE-2026-76461Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Email Gateway

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    28.3%98th pct

    KEV dates

    added due
  25. CVE-2026-85706Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    GitLab · Community Edition and Enterprise Edition

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · gitlab.com

    Attack probability (EPSS)

    93.0%99.8th pct

    KEV dates

    added due
  26. CVE-2026-42018Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Improper Authentication Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · jfrog.com

    Attack probability (EPSS)

    9.80%95th pct

    KEV dates

    added due
  27. CVE-2026-42016Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Incorrect Authorization Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    8.64%95th pct

    KEV dates

    added due
  28. CVE-2026-84869Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    ConnectWise · ScreenConnect

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    Severity

    9.9CRITICALCVSS 3.1 · 7d616e1a-3288-43b1-a0dd-0a65d3e70a49

    Attack probability (EPSS)

    0.92%59th pct

    KEV dates

    added due
  29. CVE-2026-86060Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    MikroTik · RouterOS

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    Severity

    9.2CRITICALCVSS 4.0 · cert.pl

    Attack probability (EPSS)

    6.39%93th pct

    KEV dates

    added due
  30. CVE-2026-67277Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    MikroTik · RouterOS

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · cert.pl

    Attack probability (EPSS)

    1.56%74th pct

    KEV dates

    added due
  31. CVE-2026-20079Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    88.2%99.8th pct

    KEV dates

    added due
  32. CVE-2026-19490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    23.2%98th pct

    KEV dates

    added due
  33. CVE-2025-25249Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Fortinet · Multiple Products

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    3.86%90th pct

    KEV dates

    added due
  34. CVE-2026-87491Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Chromium V8

    Google Chromium V8 Out of Bounds Write Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    3.14%87th pct

    KEV dates

    added due
  35. CVE-2026-86218Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    N-able · N-central

    N-able N-central Static Code Injection Vulnerability

    Severity

    10.0CRITICALCVSS 4.0 · a5532a13-c4dd-4202-bef1-e0b8f2f8d12b

    Attack probability (EPSS)

    12.9%96th pct

    KEV dates

    added due
  36. CVE-2026-75650Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    3.95%90th pct

    KEV dates

    added due
  37. CVE-2026-85880Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    3.62%89th pct

    KEV dates

    added due
  38. CVE-2026-81963Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Link Following Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    0.39%31th pct

    KEV dates

    added due
  39. CVE-2026-85046Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Chromium V8

    Google Chromium V8 Type Confusion Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    48.9%99th pct

    KEV dates

    added due
  40. CVE-2026-9586Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Sangoma · Switchvox

    Sangoma Switchvox SQL Injection Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 57dba5dd-1a03-47f6-8b36-e84e47d335d8

    Attack probability (EPSS)

    19.0%97th pct

    KEV dates

    added due
Showing 40 of 203

Additions by week

Most listed vendors

What the catalog is, and what it is not

The Known Exploited Vulnerabilities catalog is the list CISA uses to tell US federal agencies what to fix first. It started in November 2021 with Binding Operational Directive 22-01 and has grown by a few entries almost every week since. Each entry has a vendor, a product, a short description, the action required, the date it was added and a due date.

Why it is the first sort key here

An entry in KEV is an observation, not a prediction: someone was attacked through that vulnerability and CISA could verify it. Studies by FIRST and others show that only a small share of published CVEs is ever exploited, so knowing which ones are is worth more than any severity score.

Reading an entry

  • Date added is when CISA listed it, which can be years after the CVE was published. Old vulnerabilities enter the catalog when exploitation is noticed.
  • Due date is mandatory only for US federal civilian agencies. Recent entries often give a few days; older ones typically gave two or three weeks.
  • Ransomware use: known marks entries CISA has tied to ransomware campaigns.
  • Required action, shown on each CVE page, is CISA’s text: usually to apply the vendor’s mitigation or stop using the product.

Its limits

The catalog is not a list of everything exploited in the world. It needs a CVE ID, verifiable evidence and an available remediation, and it reflects what matters to the networks CISA protects. Treat presence in KEV as a strong reason to act and absence as no information.

Published CVEs in grey, those with confirmed exploitation in red. Illustrative, not to scale.

Questions

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities catalog is a list, maintained by the US Cybersecurity and Infrastructure Security Agency, of CVEs with reliable evidence of exploitation in the wild. It was created by Binding Operational Directive 22-01 in November 2021 and is published as a web page, a CSV and a JSON file.

What are the criteria for a CVE to enter KEV?

Three: the vulnerability has a CVE ID, there is reliable evidence that it has been actively exploited, and there is a clear remediation action such as a vendor update. A public proof of concept alone is not enough.

Who has to respect the due date?

The due date binds US Federal Civilian Executive Branch agencies, under the directive cited in the entry’s required action. Everyone else is not legally bound, but CISA recommends that all organisations prioritise KEV entries, and the date is a useful reference for urgency.

What does "Known ransomware campaign use" mean?

It is a field of the catalog with two values. "Known" means CISA is aware of the vulnerability being used in ransomware campaigns. "Unknown" means CISA has no such information, which is different from saying it has not happened.

If a CVE is not in KEV, is it safe to ignore?

No. KEV only contains what CISA could confirm, and it is focused on what matters to US federal networks. Exploitation can exist without being listed. Use EPSS and the vendor advisory to judge CVEs outside the catalog.

Related sections