Skip to content

Topic

Known Exploited Vulnerabilities catalog

CISA's KEV catalog and the binding remediation deadlines it imposes on US federal agencies, with advisory weight for private organizations.

Current stories

security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
build1 publisher

NetScaler compromise response has to unwind the controls the gateway concentrated

Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence55
build1 publisher

CISA gives federal agencies until October 2 to patch Apple's CoreGraphics flaw

CISA added Apple's CoreGraphics out-of-bounds write, CVE-2026-86950, to its KEV catalog with an October 2 deadline for federal agencies. Apple's iOS advisory is dated September 28, so agencies have four days to move iPhones, iPads and Macs onto patched builds.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence58
security4 publishers

CISA puts Ray on the KEV list, and the exploit path runs through your developers' browsers

CVE-2025-62593 carries a CVSS 9.4 and a federal remediation deadline of August 20, 2026. The unauthenticated endpoints behind it are a design decision, not an oversight.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 60%
Investor
Investor 6%

Reality

Evidence68
Adoption50
Hype gap+15
Incentives35
Confidence66
security5 publishers

Exploited within hours: MLflow SSRF and FUXA auth bypass join the emergency patch list

watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence72
Adoption55
Hype gap+20
Incentives35
Confidence70
security8 publishers

A Windchill RCE chain that never encrypts anything, and the June hunt window it opens

Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 57%
Investor
Investor 18%

Reality

Evidence68
Adoption55
Hype gap−10
Incentives60
Confidence62

Earlier coverage

  1. Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

    Security · August 26, 2026 · 7 publishers

  2. ZoomEye's CVE-2023-49105 count matches its entire ownCloud fingerprint at 152,655 hosts

    Build · September 26, 2026 · 1 publisher

  3. Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

    Security · August 28, 2026 · 7 publishers

  4. CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

    Security · August 29, 2026 · 4 publishers

  5. Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

    Security · August 28, 2026 · 10 publishers

  6. CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

    Security · September 3, 2026 · 13 publishers

  7. CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles

    Security · September 7, 2026 · 7 publishers

  8. CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later

    Security · September 10, 2026 · 2 publishers

  9. A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

    Security · September 10, 2026 · 4 publishers

  10. Cisco's own July 23 log indicator predates its August date for FMC exploitation

    Security · September 9, 2026 · 6 publishers

  11. CISA sets a September 13 deadline for the MikroTrick RouterOS chain

    Security · September 12, 2026 · 13 publishers

  12. CISA put N-able's pre-auth N-central RCE on KEV three days after the hotfix shipped

    Security · September 16, 2026 · 2 publishers

  13. Artifactory's access layer trusted an empty join key in a default install

    Build · September 19, 2026 · 1 publisher

  14. Check Point patches a Security Management zero-day it saw exploited on July 23

    Security · September 22, 2026 · 6 publishers

  15. Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

    Security · September 23, 2026 · 1 publisher

  16. Red Hat's interim mitigations cover two of the three kernel flaws CISA lists as exploited

    Build · September 22, 2026 · 1 publisher

  17. CISA gives agencies one business day to patch three exploited Linux kernel flaws

    Security · September 21, 2026 · 6 publishers

  18. ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

    Build · September 19, 2026 · 1 publisher

  19. A crafted style attribute in Magento's payment-failure reminder executes as PHP

    Build · September 19, 2026 · 1 publisher

  20. LiteLLM's MCP endpoint answered a failed key check with an empty auth object

    Build · September 16, 2026 · 1 publisher

  21. CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session

    Security · September 16, 2026 · 1 publisher

  22. CISA gives federal agencies three days to fix the ScreenConnect flaw already under attack

    Security · September 16, 2026 · 1 publisher

  23. A process created at boot lets one HTTP request take root on Cisco's firewall console

    Build · September 14, 2026 · 1 publisher

  24. Metasploit packages the SonicWall SMA1000 root chain into one module

    Security · September 11, 2026 · 1 publisher

  25. Attackers lifted the cluster join key out of self-hosted Artifactory

    Build · September 11, 2026 · 1 publisher

  26. Attackers have been planting web shells on Magento stores since September 4

    Security · September 10, 2026 · 2 publishers

  27. Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation

    Leadership · September 5, 2026 · 1 publisher

  28. CISA's exploited-vulnerability catalog now reaches the LLM gateway

    Build · September 2, 2026 · 1 publisher

  29. CISA asks buyers to make eliminated vulnerability classes a contract condition

    Security · September 1, 2026 · 1 publisher

  30. A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories

    Security · August 27, 2026 · 1 publisher

  31. CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal

    Security · August 21, 2026 · 1 publisher

  32. CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN

    Security · August 21, 2026 · 1 publisher

  33. MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list

    Build · August 20, 2026 · 1 publisher

  34. CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines

    Product · August 18, 2026 · 1 publisher