CISA Known Exploited Vulnerabilities Catalog
cisa-kev · A · active
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Authoritative for actively-exploited vulns with federal remediation deadlines. WebFetch is reliably HTTP 403 on this host (transport-side block on the routine UA, ongoing since 2026-05-06; re-confirmed 2026-05-08). REQUIRED FETCH METHOD for both main agent AND every sub-agent: `python3 tools/fetch_source.py cisa-kev` returns the full KEV JSON catalog. Do NOT call WebFetch on cisa.gov; treat the 403 as a transport block, it never demotes the source. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py cisa-kev (full KEV JSON catalog, each entry is a drillable CVE record). AVOID: Do NOT WebFetch cisa.gov, reliably 403s the routine UA. The api subcommand is the only supported path.. | 2026-07-05 admiralty audit: A (primary-authority), CISA KEV, authoritative exploited-vuln catalog; api fetch clean and current. Status stays active. | 2026-08-19: KEV JSON feed carried catalogue version 2026.08.18 and the four 2026-08-18 additions; the feed path works when every cisa.gov HTML path 403s.
Cited in 72 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 47).
- CISA KEV adds three unrelated Linux kernel flaws in one day, kTLS receive-path logic error, AF_ALG race condition, netfilter ebtables SNAT out-of-bounds write2026-09-19
- CVE-2026-87886, Acronis Backup plugin for cPanel/WHM and extension for Plesk: local privilege escalation via insecure default permissions, CISA KEV-listed (CVSS 7.8)2026-09-18
- CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)2026-09-17
- CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks2026-09-17
- CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8)2026-09-15
- CVE-2026-42016 + CVE-2026-42018, JFrog Artifactory: chaining two previously-patched token flaws turns an unauthenticated request into full administrative control in two API calls, confirmed exploited since mid-August2026-09-12
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)2026-09-12
- CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)2026-09-12
- CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)2026-09-10
- CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT2026-09-10
- September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)2026-09-09
- CVE-2026-67276 / CVE-2026-86060, MikroTik RouterOS "MikroTrick": a forged-signature SSH authentication bypass chained with a crafted-username privilege escalation reaches unauthenticated full device takeover, actively exploited2026-09-06
- CVE-2026-9586, Sangoma Switchvox: an unauthenticated XML phone-notification endpoint reaches PostgreSQL COPY TO PROGRAM, and honeypots caught exploitation nearly seven weeks after the patch shipped2026-09-03
- CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation2026-09-03
- CVE-2026-59822, BerriAI LiteLLM: a failed key check on the MCP gateway substitutes an empty auth object instead of rejecting the request, so a fabricated Bearer token opens a live MCP session2026-09-03
- A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations2026-08-28
- JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV, a CI/CD artifact-store write primitive with no published exploitation narrative2026-08-28
- Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published2026-08-28
- CVE-2026-72529 and CVE-2026-72530, a pre-auth chain on TrueConf Server's port 4307 reaches SYSTEM, and the operators use it to replace the client installer the server hands to everyone who joins a meeting2026-08-23
- CVE-2026-64849, MLflow: the SSRF guard resolves the webhook host and then throws the answer away, so one redirect turns an unauthenticated tracking server into a reader of its own cloud credentials2026-08-20
- CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed2026-08-20
- CVE-2025-62593; Ray's dashboard is defended against browsers by a User-Agent string check, and CISA now records the DNS-rebinding bypass as exploited2026-08-18
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers2026-08-12
- CVE-2026-20349, Cisco Secure Firewall ASA/FTD: one crafted HTTP request to the Remote Access SSL VPN reloads the device, exploitation confirmed, no workaround and a three-day KEV deadline2026-08-12
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since 3 August, and no CVE was ever assigned2026-08-09
- CISA publishes five protocol-level flaws in CPDLC over ATN-B1, reported by a Swiss armasuisse researcher, no mitigation available, and CISA assesses exploitation unlikely outside a lab2026-08-08
- CVE-2026-17583, Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered2026-08-05
- CVE-2026-34486, Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it2026-08-05
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed2026-08-05
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)2026-08-04
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable2026-08-03
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent2026-07-31
- VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it2026-07-29
- CVE-2026-63077, JetBrains TeamCity On-Premises: unauthenticated RCE through the agent-polling protocol, every on-prem version affected (CVSS 9.8)2026-07-29
- CVE-2025-15467, Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)2026-07-29
- CVE-2026-16812, Arista VeloCloud Orchestrator on-prem: unauthenticated OS command injection on an interface exposed by default, confirmed exploited (CVSS 10.0)2026-07-28
- CVE-2025-68686, FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited2026-07-28
- MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws2026-07-24
- CVE-2026-16232, Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)2026-07-23
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- CVE-2026-46817, Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)2026-07-16
- CVE-2023-4346, KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)2026-07-16
- CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)2026-07-15
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)2026-07-10
- CVE-2026-14480, OpenPLC v3 Runtime: authenticated arbitrary file write escalates to native RCE via the auto-compile pipeline (CVSS 9.9)2026-07-09
- CVE-2026-20744, Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation2026-07-08
- CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths2026-07-02
- CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- CVE-2026-8037, Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API2026-06-30
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- CVE-2026-40624, AVer PTC-series conference cameras: unauthenticated RCE via the management web interface2026-06-20
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory2026-06-18
- CVE-2026-0647 et al. Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH2026-06-18
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform2026-06-18
- CVE-2026-48907, Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- + 12 earlier entries