Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA KEV

Known Exploited Vulnerabilities

De KEV-catalogus bevat kwetsbaarheden waarvan CISA daadwerkelijk misbruik heeft vastgesteld, met een verplichte remediatietermijn voor Amerikaanse federale instanties en een sterke aanbeveling voor alle organisaties.

16

Vermeldingen

KEV-data: live koppeling— laatst opgehaald: 24 september 2026 om 04:16.

KEV betekent dat er bewijs bestaat van daadwerkelijke uitbuiting. Een hoge CVSS-score alleen toont dit niet aan — raadpleeg de methodologiepagina voor het verschil tussen CVE, KEV en CVSS.

16 KEV-vermeldingen

KEVPatch available

Toegevoegd op

22 september 2026

Remediation due

25 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

14 september 2026

Remediation due

17 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVEnergyPatch available

Toegevoegd op

9 september 2026

Remediation due

12 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVPatch available

Toegevoegd op

26 augustus 2026

Remediation due

29 augustus 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVGeen patch beschikbaar

Toegevoegd op

8 juni 2026

Remediation due

11 juni 2026

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

20 mei 2026

Remediation due

3 juni 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

30 maart 2026

Remediation due

2 april 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 maart 2026

Remediation due

26 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

19 december 2025

Remediation due

26 december 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 december 2025

Remediation due

24 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

16 december 2025

Remediation due

23 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

24 oktober 2025

Remediation due

14 november 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

23 september 2025

Remediation due

14 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

26 augustus 2025

Remediation due

28 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

30 juni 2025

Remediation due

21 juli 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

4 april 2025

Remediation due

11 april 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations as set forth in the CISA instructions linked below.