KEV changelog
New KEV entries
Everything CISA added to the Known Exploited Vulnerabilities catalog in the last 30 days. Every entry here is exploited in the wild — that is the catalog's entry criterion, not our assessment.
Advertisement
Sep 8, 2026 (4)
-
N-able — N-central
N-able N-central Static Code Injection Vulnerability
Our coverage: N-able N-central RCE via CVE-2026-86218 Under Active Exploitation
-
Microsoft — Windows
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Our coverage: CVE-2026-85880: Windows ALPC Heap Overflow Exploited
-
Microsoft — Windows
Microsoft Windows Link Following Vulnerability
Our coverage: CVE-2026-81963: Windows Update Stack Privilege Escalation
-
Adobe — Commerce and Magento
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Our coverage: CVE-2026-75650: Adobe Commerce RCE via Template Engine Flaw
Sep 4, 2026 (1)
-
Google — Chromium V8
Google Chromium V8 Type Confusion Vulnerability
Our coverage: Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now
Sep 2, 2026 (7)
-
Sangoma — Switchvox
Sangoma Switchvox SQL Injection Vulnerability
Our coverage: CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
-
SonicWall — SMA1000 Appliances
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
-
SonicWall — SMA1000 Appliances
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
-
JFrog — Artifactory
JFrog Artifactory Improper Authentication Vulnerability
Our coverage: CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens
-
BerriAI — LiteLLM
BerriAI LiteLLM Improper Authentication Vulnerability
Our coverage: CVE-2026-59822: BerriAI LiteLLM Authentication Bypass
-
Kestra — Kestra OSS
Kestra OSS OS Command Injection Vulnerability
Our coverage: CVE-2026-49869: Kestra OSS OS Command Injection Exploited
-
Kludex — Starlette
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Our coverage: CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass
Aug 31, 2026 (2)
-
PaperCut — NG/MF
PaperCut NG/MF Unsafe Reflection Vulnerability
Our coverage: CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit
-
PaperCut — NG/MF
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Aug 27, 2026 (3)
-
JFrog — Artifactory
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Our coverage: CVE-2026-66384: JFrog Artifactory Path Traversal Exploit
-
Linux — Kernel
Linux Kernel Unspecified Vulnerability
Our coverage: CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation
-
ownCloud — ownCloud
ownCloud Improper Authentication Vulnerability
Our coverage: CVE-2023-49105: ownCloud Improper Auth Leads to Data Compromise
Aug 26, 2026 (6)
-
Citrix — NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
-
Linux — Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
-
Ajax.NET Professional — Ajax.NET Professional
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Our coverage: CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data
-
Microsoft — SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability
-
Red Hat — Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
-
Red Hat — Libuser
Red Hat Libuser Race Condition Vulnerability
Aug 25, 2026 (1)
-
Gitea — Gitea
Gitea Code Injection Vulnerability
Our coverage: CVE-2026-60004: Gitea Code Injection Under Active Exploitation
Aug 24, 2026 (1)
-
Oracle — HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Our coverage: CVE-2026-21962: Oracle WebLogic RCE Under Active Attack
Aug 21, 2026 (1)
-
Synacor — Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Our coverage: Zimbra CVE-2026-73570 Actively Exploited: Patch Now
Aug 20, 2026 (2)
-
TrueConf — Server
TrueConf Server Code Injection Vulnerability
Our coverage: CVE-2026-72530: TrueConf Server Remote Code Execution
-
TrueConf — Server
TrueConf Server Missing Authentication for Critical Function Vulnerability
Our coverage: CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth
Aug 19, 2026 (1)
-
MLflow — MLflow
MLflow Server-Side Request Forgery Vulnerability
Our coverage: MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF
Aug 18, 2026 (4)
-
Apple — macOS
Apple macOS Improper Authentication Vulnerability
Our coverage: macOS Screen Sharing Flaw Exploited to Deploy Monero Miner
-
Broadcom — VMware vCenter
Broadcom VMware vCenter Path Traversal Vulnerability
Our coverage: CVE-2026-59310: vCenter RCE Exploited for Reverse SSH Access
-
Microsoft — SharePoint
Microsoft SharePoint Weak Authentication Vulnerability
Our coverage: CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now
-
Microsoft — Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Our coverage: CVE-2026-33824: Microsoft IKE Double Free RCE Exploit
Aug 17, 2026 (1)
-
Ray-Project — Ray
Ray-Project Ray Code Injection Vulnerability
Our coverage: CISA Warns of Active Ray Exploit and Medusa Ransomware Campaign CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild
Aug 11, 2026 (3)
-
Metabase — Metabase
Metabase SQL Injection Vulnerability
Our coverage: CVE-2026-72898: Metabase SQL Injection Active Exploitation
-
Microsoft — Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Our coverage: CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day
-
Cisco — Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Our coverage: CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit
Source: CISA KEV catalog. Refreshed every ingestion run. See also the full CVE tracker.