Skip to content

standard

CISA Known Exploited Vulnerabilities Catalog

A U.S. CISA-maintained catalog of vulnerabilities confirmed to be actively exploited, used to prioritize patching across federal agencies and industry.

Known aliases

  • catalog of actively exploited vulnerabilities
  • CISA KEV
  • CISA KEV Catalog
  • KEV
  • KEV catalog
  • KEV list
  • Known Exploited Vulnerabilities catalog
  • Known Exploited Vulnerabilities list

Relationships

No evidence-backed relationships are recorded.

Current stories

security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
security7 publishers

Fortinet tells FortiMail admins to disable IBE while an exploited CVSS 9.8 flaw awaits fixes

Fortinet says attackers are exploiting a CVSS 9.8 unauthenticated file-write flaw in FortiMail, and no fixed release has shipped yet. Until builds arrive, its two workarounds are the only protection, including for 7.2 users told to move to a 7.4 branch that is still unpatched.

Perspective Coverage

7 publishers
Builder
Builder 15%
Operator
Operator 82%
Investor
Investor 3%

Reality

Evidence78
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence74
security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security8 publishers

DIVD traces its breach to two chained zero-days in its own Zammad helpdesk

DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.

Perspective Coverage

8 publishers
Builder
Builder 27%
Operator
Operator 64%
Investor
Investor 9%

Reality

Evidence68
Adoption35
Hype gap+25
Incentives40
Confidence66
security9 publishers

CISA gives federal agencies until October 2 to patch Apple's exploited CoreGraphics flaw

CISA added Apple's CoreGraphics zero-day CVE-2026-86950 to its KEV catalog, giving federal agencies until October 2, 2026 to patch. Only federal civilian agencies are bound by that date. Every other Apple fleet sets its own deadline for a bug Apple links to targeted attacks.

Perspective Coverage

9 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence74
Adoption
Insufficient
Hype gap+20
Incentives25
Confidence70
build1 publisher

NetScaler compromise response has to unwind the controls the gateway concentrated

Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence55
build1 publisher

CISA gives federal agencies until October 2 to patch Apple's CoreGraphics flaw

CISA added Apple's CoreGraphics out-of-bounds write, CVE-2026-86950, to its KEV catalog with an October 2 deadline for federal agencies. Apple's iOS advisory is dated September 28, so agencies have four days to move iPhones, iPads and Macs onto patched builds.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence58
security5 publishers

SharePoint flaw CVE-2026-65660 came under attack within days of Viettel's technical write-up

Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 68%
Investor
Investor 6%

Reality

Evidence74
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence70
build1 publisher

Cisco email gateway flaw runs attacker SQL as root the moment it parses a message

CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
security5 publishers

Three days from patch to probe: SAP Commerce Cloud RCE is already being hunted

CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence70
Adoption55
Hype gap+25
Incentives40
Confidence68

Earlier coverage

  1. CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive

    Security · August 19, 2026 · 2 publishers

  2. One Gitea Signup Now Buys Shell Access. Patch, Close Registration, Audit Hooks Before August 28.

    Build · August 26, 2026 · 1 publisher

  3. ZoomEye's CVE-2023-49105 count matches its entire ownCloud fingerprint at 152,655 hosts

    Build · September 26, 2026 · 1 publisher

  4. CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

    Security · August 29, 2026 · 4 publishers

  5. CISA ties federal patch deadlines to four yes-or-no questions about each CVE

    Security · September 6, 2026 · 2 publishers

  6. A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

    Security · September 10, 2026 · 4 publishers

  7. A hand-debugged Python toolkit turned marimo CVE-2026-39987 into bastion SSH in eight seconds

    Security · September 11, 2026 · 3 publishers

  8. Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29

    Security · September 15, 2026 · 2 publishers

  9. Certification rules slow election-system patching, CISA's 2026 security plan says

    Security · September 25, 2026 · 2 publishers

  10. Attackers are exploiting CVE-2026-93952 in VeloCloud Orchestrators that authenticate Edges by certificate

    Security · September 22, 2026 · 4 publishers

  11. Red Heron-linked actor turned mid-July wp2shell exploits into 18,566 stolen government records

    Security · September 22, 2026 · 1 publisher

  12. Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000

    Build · September 21, 2026 · 1 publisher

  13. Firewalling RouterOS SSH to a management network removes MikroTrick's precondition

    Build · September 19, 2026 · 1 publisher

  14. N-able's fourth hotfix is the one that closes the N-central code injection

    Build · September 19, 2026 · 1 publisher

  15. ZoomEye's SonicWall SMA fingerprint returns 7 records against Shadowserver's several hundred

    Build · September 19, 2026 · 1 publisher

  16. CISA gave federal SonicWall SMA 1000 operators three days to patch a pre-auth SSRF

    Build · September 19, 2026 · 1 publisher

  17. A prohibited leading character in a RouterOS username rewrites the session's policy mask

    Build · September 16, 2026 · 1 publisher

  18. Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass

    Build · September 18, 2026 · 1 publisher

  19. A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes

    Build · September 18, 2026 · 1 publisher

  20. CVE-2026-77179 let sandboxed agent code write anywhere the macOS host account could

    Security · September 17, 2026 · 1 publisher

  21. CISA gives federal agencies three days to fix the ScreenConnect flaw already under attack

    Security · September 16, 2026 · 1 publisher

  22. One slash in a Host header moves the path Starlette's middleware checks

    Build · September 16, 2026 · 1 publisher

  23. A crafted email is already getting root on unpatched Cisco Secure Email Gateways

    Security · September 15, 2026 · 1 publisher

  24. Attackers have been pushing VBScript through live ScreenConnect sessions since August 20

    Security · September 14, 2026 · 1 publisher

  25. A nuclei template hit Langflow's unauthenticated build endpoint 20 hours after disclosure

    Security · September 11, 2026 · 1 publisher

  26. Metasploit packages the SonicWall SMA1000 root chain into one module

    Security · September 11, 2026 · 1 publisher

  27. Fourteen percent of attack actions raised an alert across Picus's 338 million simulations

    Security · September 9, 2026 · 1 publisher

  28. Attackers seized MSP N-central servers through the bypass N-able's incomplete fix left open

    Security · September 9, 2026 · 1 publisher

  29. cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

    Security · September 9, 2026 · 1 publisher

  30. Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers

    Security · September 5, 2026 · 4 publishers

  31. Google patches a V8 type confusion already being exploited against Chrome users

    Security · September 4, 2026 · 9 publishers

  32. Unpatched TeamCity server gave attackers AWS IAM credentials from JetBrains' Cadence backup

    Security · September 5, 2026 · 1 publisher

  33. Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation

    Leadership · September 5, 2026 · 1 publisher

  34. CISA asks buyers to make eliminated vulnerability classes a contract condition

    Security · September 1, 2026 · 1 publisher

  35. Two product names and a three-day clock: the case for patching the pipeline first

    Security · August 26, 2026 · 1 publisher

  36. TrueConf's update directory is the delivery route: two KEV bugs, one swapped installer

    Build · August 21, 2026 · 1 publisher

  37. CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN

    Security · August 21, 2026 · 1 publisher

  38. MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list

    Build · August 20, 2026 · 1 publisher

  39. One packet reboots your Cisco VPN box, and Cisco will not say who is firing it

    Security · August 19, 2026 · 1 publisher

  40. SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent

    Security · August 14, 2026 · 1 publisher