Skip to content

standard

CISA Known Exploited Vulnerabilities Catalog

A CISA database listing software and hardware vulnerabilities confirmed to be actively exploited, used to prioritize patching across government and industry.

Known aliases

  • CISA Known Exploited Vulnerabilities Catalog
  • Known Exploited Vulnerabilities

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Windows DNS Server's 9.8 bug takes one unauthenticated packet to port 53

Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
build1 publisher

Putting KEV and EPSS ahead of CVSS lifts a 6.5 finding above a 9.1

Ranking by KEV, then EPSS, then CVSS puts a 6.5 with 0.61 exploit odds ahead of a 9.1 at 0.02 in a Dev.to triage guide's worked example. The order is sound, though the backlog savings it promises rest on five hypothetical findings and CVE-wide statistics the post does not source.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence50
security6 publishers

14,530 Dahua cameras in 35 days, and the only exotic tool was masscan

Hunt.io says one operator brute-forced its way through more than 14,000 internet-exposed cameras in five weeks. The tooling was borrowed; the exposure did the work.

Perspective Coverage

6 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence64
security6 publishers

Unauthenticated attackers can forge admin tokens on default self-managed Artifactory installs

CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.

Publishers:bleepingcomputer.comcvereports.comdocs.jfrog.comscworld.comsecurityweek.comthehackernews.com

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 63%
Investor
Investor 9%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence64
security4 publishers

Any PostgreSQL replication account can load a shared library as the postgres OS user

CVE-2026-6471 has sat in every PostgreSQL release since 9.4 shipped in 2014. Cyera says the plugin name in a replication slot request reaches dlopen() unvalidated, which makes the fix a privilege audit as much as a patch.

Perspective Coverage

4 publishers
Builder
Builder 32%
Operator
Operator 59%
Investor
Investor 9%

Reality

Evidence74
Adoption55
Hype gap+24
Incentives58
Confidence72
security5 publishers

Check Point patches two 9.8 VPN certificate flaws without naming what triggers them

Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.

Perspective Coverage

5 publishers
Builder
Builder 15%
Operator
Operator 74%
Investor
Investor 11%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62

Earlier coverage

  1. ToolShell's author publishes a working code-execution exploit for SharePoint's CVE-2026-65660

    Security · September 22, 2026 · 2 publishers

  2. Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

    Security · September 23, 2026 · 6 publishers

  3. GreyNoise ties 18,566 stolen government records and 996 harvested Zyxel switches to one actor

    Build · September 22, 2026 · 1 publisher

  4. A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable

    Build · September 22, 2026 · 1 publisher

  5. Delinea fixed two unauthenticated critical flaws in its credential vault 18 days before disclosing them

    Science · September 18, 2026 · 1 publisher

  6. Verizon's 43-day median patch time, against a five-day weaponization clock

    Security · September 17, 2026 · 1 publisher

  7. A published ProFTPD mod_sql exploit needs a login and a privileged PostgreSQL role

    Build · September 16, 2026 · 1 publisher

  8. A query string walks past server.fs.deny on Vite dev servers left on a public port

    Build · September 15, 2026 · 2 publishers

  9. Exploitation beat CVE publication for about 256 vulnerabilities last year

    Build · September 11, 2026 · 1 publisher

  10. Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year

    Security · September 10, 2026 · 1 publisher

  11. Two agent sandboxes ship an unauthenticated shell endpoint on every interface

    Build · September 6, 2026 · 1 publisher

  12. Guest admin is enough to break out of VMware Workstation onto the host

    Security · September 5, 2026 · 3 publishers

  13. Counting from the vendor advisory stretches the exploitation window to 116 days

    Build · September 5, 2026 · 1 publisher

  14. August's 398-CVE Patch Tuesday moves the bottleneck to the test bench

    Security · September 4, 2026 · 1 publisher

  15. A dropped authorization check exposes GeoNetwork geoportal backends to unauthenticated RCE

    Security · September 2, 2026 · 1 publisher

  16. Cohesity's field CISO ranks KEV above EPSS above CVSS in a tiebreaker she would hand an analyst

    Security · August 31, 2026 · 1 publisher

  17. Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain

    Build · August 31, 2026 · 1 publisher

  18. Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test

    Security · August 31, 2026 · 1 publisher

  19. Hive's SAML validator hands out a session to any Bearer token you forge

    Build · August 30, 2026 · 1 publisher

  20. Exposed AI tooling now outnumbers exposed ICS hosts by more than two to one

    Security · August 28, 2026 · 1 publisher

  21. One shared-hosting customer can take root on a whole cPanel server through parked domains

    Security · August 28, 2026 · 1 publisher

  22. Someone enumerated LiteLLM's key tables 36 hours after the advisory hit defender feeds

    Security · August 28, 2026 · 1 publisher

  23. Self-hosted ServiceNow operators inherit three unauthenticated CVSS 10.0 flaws to patch themselves

    Security · August 28, 2026 · 2 publishers

  24. Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success

    Security · August 27, 2026 · 1 publisher

  25. Frontier AI can find the bugs faster. The patch queue is the number nobody published.

    Security · August 26, 2026 · 1 publisher

  26. Two datasets, one vendor list: edge risk is a procurement problem, not a CVE queue

    Security · August 26, 2026 · 1 publisher

  27. Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor

    Security · August 26, 2026 · 1 publisher

  28. Vulnerability disclosures bent upward in 2026. Algorithm records did not.

    Security · August 25, 2026 · 1 publisher

  29. 8,900 hostile requests, none of them dangerous: reading a Next.js site's own edge log

    Build · August 17, 2026 · 1 publisher

  30. Three Zoom annotation bugs made every screen share a two-way takeover path

    Security · August 15, 2026 · 2 publishers