Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA KEV

Known Exploited Vulnerabilities

De KEV-catalogus bevat kwetsbaarheden waarvan CISA daadwerkelijk misbruik heeft vastgesteld, met een verplichte remediatietermijn voor Amerikaanse federale instanties en een sterke aanbeveling voor alle organisaties.

3

Vermeldingen

KEV-data: live koppeling— laatst opgehaald: 24 september 2026 om 04:17.

KEV betekent dat er bewijs bestaat van daadwerkelijke uitbuiting. Een hoge CVSS-score alleen toont dit niet aan — raadpleeg de methodologiepagina voor het verschil tussen CVE, KEV en CVSS.

3 KEV-vermeldingen

KEVEnergyPatch available

Toegevoegd op

9 september 2026

Remediation due

12 september 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

10 juli 2025

Remediation due

11 juli 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

30 juni 2025

Remediation due

21 juli 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.