Skip to main content

KEV changelog

New KEV entries

Everything CISA added to the Known Exploited Vulnerabilities catalog in the last 30 days. Every entry here is exploited in the wild — that is the catalog's entry criterion, not our assessment.

Added: 25 Ransomware-linked: 0 Covered by our reporting: 14 RSS

Advertisement

Jul 29, 2026 (1)

Jul 27, 2026 (2)

Jul 22, 2026 (2)

Jul 21, 2026 (4)

Jul 16, 2026 (3)

Jul 15, 2026 (2)

  • CVE-2026-46817 exploited federal due 2026-07-18

    Oracle — E-Business Suite

    Oracle E-Business Suite Improper Privilege Management Vulnerability

  • CVE-2023-4346 exploited federal due 2026-07-29

    KNX Association — KNX Protocol Connection Authorization Option 1

    KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Jul 14, 2026 (4)

Jul 13, 2026 (1)

  • CVE-2008-4128 exploited federal due 2026-07-16

    Cisco — IOS

    Cisco IOS Cross-Site Request Forgery Vulnerability

Jul 10, 2026 (2)

Jul 7, 2026 (4)

Source: CISA KEV catalog. Refreshed every ingestion run. See also the full CVE tracker.