Skip to content

standard

Known Exploited Vulnerabilities catalog

CISA-maintained list of vulnerabilities confirmed exploited in the wild; inclusion triggers binding federal remediation deadlines.

Known aliases

  • Known Exploited Vulnerability catalog

Relationships

No evidence-backed relationships are recorded.

Current stories

security4 publishers

Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 68%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence70
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80

Earlier coverage

  1. CISA marks which KEV vulnerabilities ransomware crews are known to use

    Security · September 12, 2026 · 1 publisher

  2. Attackers have been planting web shells on Magento stores since September 4

    Security · September 10, 2026 · 2 publishers

  3. Unauthenticated file exposure puts ownCloud first in CISA's newest KEV batch

    Leadership · September 4, 2026 · 1 publisher

  4. Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers

    Security · September 3, 2026 · 3 publishers

  5. CISA's exploited-vulnerability catalog now reaches the LLM gateway

    Build · September 2, 2026 · 1 publisher

  6. A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories

    Security · August 27, 2026 · 1 publisher

  7. CISA's KEV triage guidance tells agencies to collect RAM before they patch

    Security · August 17, 2026 · 1 publisher