Skip to main content

KEV changelog

New KEV entries

Everything CISA added to the Known Exploited Vulnerabilities catalog in the last 30 days. Every entry here is exploited in the wild — that is the catalog's entry criterion, not our assessment.

Added: 37 Ransomware-linked: 0 Covered by our reporting: 29 RSS

Advertisement

Sep 8, 2026 (4)

Sep 4, 2026 (1)

Sep 2, 2026 (7)

Aug 31, 2026 (2)

Aug 27, 2026 (3)

Aug 26, 2026 (6)

  • CVE-2026-8452 exploited federal due 2026-08-29

    Citrix — NetScaler ADC and NetScaler Gateway

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

  • CVE-2022-0995 exploited federal due 2026-09-09

    Linux — Kernel

    Linux Kernel Out-of-Bounds Write Vulnerability

  • CVE-2021-23758 exploited federal due 2026-09-09

    Ajax.NET Professional — Ajax.NET Professional

    Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

    Our coverage: CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data

  • CVE-2019-1068 exploited federal due 2026-08-29

    Microsoft — SQL Server

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2015-5287 exploited federal due 2026-09-09

    Red Hat — Automatic Bug Reporting Tool

    Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

  • CVE-2015-3246 exploited federal due 2026-09-09

    Red Hat — Libuser

    Red Hat Libuser Race Condition Vulnerability

Aug 25, 2026 (1)

Aug 24, 2026 (1)

Aug 21, 2026 (1)

Aug 20, 2026 (2)

Aug 19, 2026 (1)

Aug 18, 2026 (4)

Aug 17, 2026 (1)

Aug 11, 2026 (3)

Source: CISA KEV catalog. Refreshed every ingestion run. See also the full CVE tracker.