Direkt zum Inhalt
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA KEV

Known Exploited Vulnerabilities

Der KEV-Katalog enthält Schwachstellen, für die CISA eine tatsächliche Ausnutzung festgestellt hat, mit einer verpflichtenden Behebungsfrist für US-Bundesbehörden und einer dringenden Empfehlung für alle Organisationen.

16

Einträge

KEV-Daten: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 05:13.

KEV bedeutet, dass Belege für eine tatsächliche Ausnutzung vorliegen. Ein hoher CVSS-Wert allein belegt dies nicht — siehe die Methodikseite für den Unterschied zwischen CVE, KEV und CVSS.

16 KEV-Einträge

KEVPatch verfügbar

Hinzugefügt am

22. September 2026

Behebung fällig

25. September 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch verfügbar

Hinzugefügt am

14. September 2026

Behebung fällig

17. September 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVEnergiePatch verfügbar

Hinzugefügt am

9. September 2026

Behebung fällig

12. September 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch verfügbar

Hinzugefügt am

26. August 2026

Behebung fällig

29. August 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVKein Patch verfügbar

Hinzugefügt am

8. Juni 2026

Behebung fällig

11. Juni 2026

Ransomware-Nutzung

bestätigt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

20. Mai 2026

Behebung fällig

3. Juni 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

30. März 2026

Behebung fällig

2. April 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

5. März 2026

Behebung fällig

26. März 2026

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

19. Dezember 2025

Behebung fällig

26. Dezember 2025

Ransomware-Nutzung

bestätigt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

17. Dezember 2025

Behebung fällig

24. Dezember 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

16. Dezember 2025

Behebung fällig

23. Dezember 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

24. Oktober 2025

Behebung fällig

14. November 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

23. September 2025

Behebung fällig

14. Oktober 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

26. August 2025

Behebung fällig

28. August 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergieKein Patch verfügbar

Hinzugefügt am

30. Juni 2025

Behebung fällig

21. Juli 2025

Ransomware-Nutzung

unbekannt

Erforderliche Maßnahme: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVKein Patch verfügbar

Hinzugefügt am

4. April 2025

Behebung fällig

11. April 2025

Ransomware-Nutzung

bestätigt

Erforderliche Maßnahme: Apply mitigations as set forth in the CISA instructions linked below.