CISA Known Exploited Vulnerabilities Catalog
cisa-kev · A · active
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Authoritative for actively-exploited vulns with federal remediation deadlines. WebFetch is reliably HTTP 403 on this host (transport-side block on the routine UA, ongoing since 2026-05-06; re-confirmed 2026-05-08). REQUIRED FETCH METHOD for both main agent AND every sub-agent: `python3 tools/fetch_source.py cisa-kev` returns the full KEV JSON catalog. Do NOT call WebFetch on cisa.gov; treat the 403 as a transport block — it never demotes the source. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py cisa-kev (full KEV JSON catalog, each entry is a drillable CVE record). AVOID: Do NOT WebFetch cisa.gov — reliably 403s the routine UA. The api subcommand is the only supported path.. | 2026-07-05 admiralty audit: A (primary-authority) — CISA KEV, authoritative exploited-vuln catalog; api fetch clean and current. Status stays active.
Cited in 54 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 32).
- CVE-2026-63077 — TeamCity On-Premises moves to confirmed exploitation on the CISA KEV catalog, nine days after JetBrains said it had seen none2026-08-06
- CVE-2026-17583 — Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered2026-08-05
- N-able N-central post-exploitation, unpacked: six remote-access tools pushed to managed endpoints, a Cloudflare tunnel renamed as a Microsoft updater, and an EDR-evasion driver staged from a remote-support directory2026-08-05
- CVE-2026-9198 — a third Langflow pre-auth code-execution path reaches CISA KEV: an unauthenticated auto-login endpoint mints a superuser token, and code validation executes what it is handed2026-08-05
- CVE-2026-34486 — Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it2026-08-05
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed2026-08-05
- Water-sector PLC lockouts went from one state to seven inside the week, and the European exposure got counted — 86% of 4,117 internet-facing Siemens S7-1200 units sit in four EU countries, reached through mobile carriers2026-08-02
- 2026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchain2026-08-02
- Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply2026-08-02
- The exploited surface this week was the management plane itself — VeloCloud Orchestrator, Secure FMC, Check Point SmartConsole, FortiOS SSL-VPN and exposed BMCs, and on several of them what the attacker obtained outlives the upgrade2026-08-02
- Water-utility PLC lockouts spread to seven US states — FBI names the targeted controllers, and a Censys scan puts 86% of exposed Siemens S7-1200 units in four European countries2026-08-01
- CVE-2025-15467 — Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)2026-07-29
- CVE-2026-16812 — Arista VeloCloud Orchestrator on-prem: unauthenticated OS command injection on an interface exposed by default, confirmed exploited (CVSS 10.0)2026-07-28
- CVE-2025-68686 — FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited2026-07-28
- 2026-W30 vulnerability status roll-up — five CVEs crossed into confirmed exploitation/KEV, three more carry public exploit code, and a dense CVSS-9-to-10 tail hit edge, ERP, OT and file-transfer2026-07-26
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws2026-07-24
- CVE-2026-16232 — Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)2026-07-23
- CVE-2026-0770 — Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- 2026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT2026-07-19
- OT/ICS carried a full week of high-severity advisories across energy, water, transport and manufacturing — a CVSS-10 debug-port takeover, a persistent-root switch chain, an early-boot coupler backdoor, and a KEV-listed building-automation lockout with no software fix2026-07-19
- Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation2026-07-19
- CVE-2026-58644 — SharePoint Server deserialization RCE moves from 'Exploitation More Likely' to confirmed exploited and CISA KEV-listed2026-07-17
- CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)2026-07-16
- CVE-2023-4346 — KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)2026-07-16
- CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)2026-07-15
- CVE-2026-48939 — iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)2026-07-10
- CVE-2026-14480 — OpenPLC v3 Runtime: authenticated arbitrary file write escalates to native RCE via the auto-compile pipeline (CVSS 9.9)2026-07-09
- CVE-2026-48282 — Adobe ColdFusion path-traversal RCE now actively exploited and CISA KEV-listed2026-07-08
- CVE-2026-20744 — Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation2026-07-08
- Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle2026-07-05
- CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- Looking ahead — 2026-W262026-06-29
- FortiBleed2026-06-29
- CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited (CISA KEV)2026-06-22
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH2026-06-22
- FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance2026-06-20
- CVE-2026-52806 — Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface2026-06-20
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH2026-06-18
- BSI flags 13 vulnerabilities patched in Zammad 7.1 — admin privilege escalation in a DACH public-sector helpdesk platform2026-06-18
- CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited in the wild (CISA KEV)2026-06-16
- Linux cgroups v1 release_agent container escape (CVE-2022-0492) re-enters active exploitation2026-06-03
- CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation2026-06-03
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries2026-05-28
- CVE-2026-34926 — Trend Micro Apex One On-Premise: post-auth directory traversal by admin-credential holder injects code deployed fleet-wide to all managed agents (CISA KEV, ITW)2026-05-22
- CVE-2026-20223 — Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround2026-05-22
- CVE-2025-34291 — Langflow AI Workflow Platform: CORS misconfiguration + SameSite=None refresh token enables cross-origin token theft (CISA KEV, ITW, Flodric botnet)2026-05-22
- Two CISA KEV additions under active exploitation — Trend Micro Apex One and Langflow2026-05-18
- Exchange CVE-2026-42897 — Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation2026-05-17
- CVE-2026-31431 "Copy Fail" — CISA KEV deadline 2026-05-15 approaching; Microsoft documents Linux LPE cluster post-compromise chain2026-05-09
- CVE-2026-0300 — Palo Alto PAN-OS Captive Portal KEV deadline TODAY (2026-05-09); no patch exists; first patches expected 2026-05-13; CL-STA-1132 post-exploitation detail2026-05-09