Direct naar inhoud
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA KEV

Known Exploited Vulnerabilities

De KEV-catalogus bevat kwetsbaarheden waarvan CISA daadwerkelijk misbruik heeft vastgesteld, met een verplichte remediatietermijn voor Amerikaanse federale instanties en een sterke aanbeveling voor alle organisaties.

34

Vermeldingen

KEV-data: live koppeling — laatst opgehaald: 25 juli 2026 om 01:16.

KEV betekent dat er bewijs bestaat van daadwerkelijke uitbuiting. Een hoge CVSS-score alleen toont dit niet aan — raadpleeg de methodologiepagina voor het verschil tussen CVE, KEV en CVSS.

34 KEV-vermeldingen

KEVGeen patch beschikbaar

Toegevoegd op

8 juni 2026

Remediation due

11 juni 2026

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-31431

Onbekend productABB

KEVGeen patch beschikbaar

Toegevoegd op

1 mei 2026

Remediation due

15 mei 2026

Ransomwaregebruik

onbekend

Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

30 maart 2026

Remediation due

2 april 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 maart 2026

Remediation due

26 maart 2026

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

19 december 2025

Remediation due

26 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 december 2025

Remediation due

24 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-13223

CADRASiemens

KEVGeen patch beschikbaar

Toegevoegd op

19 november 2025

Remediation due

10 december 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

7 oktober 2025

Remediation due

28 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

29 september 2025

Remediation due

20 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-10585

CADRASiemens

KEVGeen patch beschikbaar

Toegevoegd op

23 september 2025

Remediation due

14 oktober 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

26 augustus 2025

Remediation due

28 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 augustus 2025

Remediation due

26 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

5 augustus 2025

Remediation due

26 augustus 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

10 juli 2025

Remediation due

11 juli 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

30 juni 2025

Remediation due

21 juli 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

4 april 2025

Remediation due

11 april 2025

Ransomwaregebruik

bevestigd

Required action: Apply mitigations as set forth in the CISA instructions linked below.

KEVGeen patch beschikbaar

Toegevoegd op

3 maart 2025

Remediation due

24 maart 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

3 maart 2025

Remediation due

24 maart 2025

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

3 december 2024

Remediation due

24 december 2024

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

25 november 2024

Remediation due

16 december 2024

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

30 mei 2024

Remediation due

20 juni 2024

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

31 januari 2024

Remediation due

2 februari 2024

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVEnergyGeen patch beschikbaar

Toegevoegd op

17 januari 2024

Remediation due

7 februari 2024

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

17 januari 2024

Remediation due

24 januari 2024

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 januari 2024

Remediation due

22 januari 2024

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

10 januari 2024

Remediation due

22 januari 2024

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

11 december 2023

Remediation due

18 december 2023

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

31 oktober 2023

Remediation due

21 november 2023

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

31 oktober 2023

Remediation due

21 november 2023

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

18 september 2023

Remediation due

9 oktober 2023

Ransomwaregebruik

onbekend

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

19 juli 2023

Remediation due

9 augustus 2023

Ransomwaregebruik

bevestigd

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

KEVGeen patch beschikbaar

Toegevoegd op

25 augustus 2022

Remediation due

15 september 2022

Ransomwaregebruik

onbekend

Required action: The impacted product is end-of-life and should be disconnected if still in use.

KEVGeen patch beschikbaar

Toegevoegd op

15 april 2022

Remediation due

6 mei 2022

Ransomwaregebruik

onbekend

Required action: The impacted product is end-of-life and should be disconnected if still in use.

KEVGeen patch beschikbaar

Toegevoegd op

25 maart 2022

Remediation due

15 april 2022

Ransomwaregebruik

onbekend

Required action: The impacted product is end-of-life and should be disconnected if still in use.