Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA KEV

Known Exploited Vulnerabilities

De KEV-catalogus bevat kwetsbaarheden waarvan CISA daadwerkelijk misbruik heeft vastgesteld, met een verplichte remediatietermijn voor Amerikaanse federale instanties en een sterke aanbeveling voor alle organisaties.

66

Vermeldingen

KEV-data: live koppeling— laatst opgehaald: 23 september 2026 om 01:38.

KEV betekent dat er bewijs bestaat van daadwerkelijke uitbuiting. Een hoge CVSS-score alleen toont dit niet aan — raadpleeg de methodologiepagina voor het verschil tussen CVE, KEV en CVSS.

66 KEV-vermeldingen

KEVPatch available

Toegevoegd op

22 september 2026

Remediation due

25 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

18 september 2026

Remediation due

21 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

14 september 2026

Remediation due

17 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVEnergyPatch available

Toegevoegd op

9 september 2026

Remediation due

12 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

9 september 2026

Remediation due

12 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

8 september 2026

Remediation due

22 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

8 september 2026

Remediation due

22 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

26 augustus 2026

Remediation due

29 augustus 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

11 augustus 2026

Remediation due

25 augustus 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVGeen patch beschikbaar

Toegevoegd op

8 juni 2026

Remediation due

11 juni 2026

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

20 mei 2026

Remediation due

3 juni 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

20 mei 2026

Remediation due

3 juni 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

1 mei 2026

Remediation due

15 mei 2026

Ransomwaregebruik

onbekend

Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

28 april 2026

Remediation due

12 mei 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 april 2026

Remediation due

27 april 2026

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 april 2026

Remediation due

27 april 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

30 maart 2026

Remediation due

2 april 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 maart 2026

Remediation due

26 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 februari 2026

Remediation due

10 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 februari 2026

Remediation due

3 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 februari 2026

Remediation due

3 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 februari 2026

Remediation due

3 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 februari 2026

Remediation due

3 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 februari 2026

Remediation due

3 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 januari 2026

Remediation due

3 februari 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

29 december 2025

Remediation due

19 januari 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

19 december 2025

Remediation due

26 december 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 december 2025

Remediation due

24 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

16 december 2025

Remediation due

23 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

9 december 2025

Remediation due

30 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

19 november 2025

Remediation due

10 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

12 november 2025

Remediation due

3 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

24 oktober 2025

Remediation due

14 november 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

20 oktober 2025

Remediation due

10 november 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

14 oktober 2025

Remediation due

4 november 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

14 oktober 2025

Remediation due

4 november 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

7 oktober 2025

Remediation due

28 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

6 oktober 2025

Remediation due

27 oktober 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

6 oktober 2025

Remediation due

27 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

6 oktober 2025

Remediation due

27 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

29 september 2025

Remediation due

20 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

23 september 2025

Remediation due

14 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

26 augustus 2025

Remediation due

28 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 augustus 2025

Remediation due

26 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 augustus 2025

Remediation due

26 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

10 juli 2025

Remediation due

11 juli 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

30 juni 2025

Remediation due

21 juli 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 juni 2025

Remediation due

1 juli 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 mei 2025

Remediation due

3 juni 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 mei 2025

Remediation due

3 juni 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 mei 2025

Remediation due

3 juni 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 mei 2025

Remediation due

3 juni 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

13 mei 2025

Remediation due

3 juni 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 april 2025

Remediation due

8 mei 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

8 april 2025

Remediation due

29 april 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

4 april 2025

Remediation due

11 april 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations as set forth in the CISA instructions linked below.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 maart 2025

Remediation due

1 april 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

3 maart 2025

Remediation due

24 maart 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

6 februari 2025

Remediation due

27 februari 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

21 november 2023

Remediation due

12 december 2023

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 oktober 2023

Remediation due

31 oktober 2023

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.