CISA KEV
Known Exploited Vulnerabilities
De KEV-catalogus bevat kwetsbaarheden waarvan CISA daadwerkelijk misbruik heeft vastgesteld, met een verplichte remediatietermijn voor Amerikaanse federale instanties en een sterke aanbeveling voor alle organisaties.
16
Vermeldingen
KEV-data: live koppeling— laatst opgehaald: 24 september 2026 om 04:16.
KEV betekent dat er bewijs bestaat van daadwerkelijke uitbuiting. Een hoge CVSS-score alleen toont dit niet aan — raadpleeg de methodologiepagina voor het verschil tussen CVE, KEV en CVSS.
16 KEV-vermeldingen
Toegevoegd op
22 september 2026
Remediation due
25 september 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Toegevoegd op
14 september 2026
Remediation due
17 september 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Toegevoegd op
9 september 2026
Remediation due
12 september 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Toegevoegd op
26 augustus 2026
Remediation due
29 augustus 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Toegevoegd op
8 juni 2026
Remediation due
11 juni 2026
Ransomwaregebruik
bevestigd
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
20 mei 2026
Remediation due
3 juni 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
30 maart 2026
Remediation due
2 april 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
5 maart 2026
Remediation due
26 maart 2026
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
19 december 2025
Remediation due
26 december 2025
Ransomwaregebruik
bevestigd
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
17 december 2025
Remediation due
24 december 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
16 december 2025
Remediation due
23 december 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
24 oktober 2025
Remediation due
14 november 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
23 september 2025
Remediation due
14 oktober 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
26 augustus 2025
Remediation due
28 augustus 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
30 juni 2025
Remediation due
21 juli 2025
Ransomwaregebruik
onbekend
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Toegevoegd op
4 april 2025
Remediation due
11 april 2025
Ransomwaregebruik
bevestigd
Required action: Apply mitigations as set forth in the CISA instructions linked below.