CISA KEV
Known Exploited Vulnerabilities
The KEV catalogue contains vulnerabilities for which CISA has established actual exploitation, with a mandatory remediation deadline for US federal agencies and a strong recommendation for all organisations.
3
Entries
KEV data: live connection— last retrieved: 24 September 2026 at 06:18.
KEV means there is evidence of actual exploitation. A high CVSS score alone does not demonstrate this — see the methodology page for the difference between CVE, KEV and CVSS.
3 KEV entries
Added on
9 September 2026
Remediation due
12 September 2026
Ransomware use
unknown
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Added on
10 July 2025
Remediation due
11 July 2025
Ransomware use
confirmed
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Added on
30 June 2025
Remediation due
21 July 2025
Ransomware use
unknown
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.