CISA Known Exploited Vulnerabilities (KEV)

156 vulnerabilities confirmed by CISA to be actively exploited in the wild. These require immediate attention — they are not theoretical risks, attackers are using them right now.

Active Exploitation Confirmed
CISA's BOD 22-01 mandates federal agencies patch these vulnerabilities. All organizations should treat KEV entries as highest priority.
Get KEV Alerts
68
Critical
71
High
17
Medium
0
Low
156
Total KEV
Sort: Date Added CVSS Score EPSS Score
CVE-2026-1731
KEV EPSS 61.4% 9.8

BeyondTrust Remote Support and older Privileged Remote Access versions contain a critical pre-authentication remote code execution vulnerability. Unau...

Added to KEV: Feb 13, 2026
CVE-2024-43468
KEV EPSS 87.5% 9.8

CVE-2024-43468 is a critical SQL injection vulnerability in Microsoft Configuration Manager that allows remote attackers to execute arbitrary code on ...

Added to KEV: Feb 12, 2026
CVE-2026-20700
KEV EPSS 0.1% 7.8

A memory corruption vulnerability in Apple operating systems allows attackers with memory write capability to execute arbitrary code. This affects wat...

Added to KEV: Feb 12, 2026
CVE-2025-15556
KEV EPSS 3.2% 7.5

This vulnerability allows attackers to intercept Notepad++ update traffic and replace legitimate updates with malicious installers. When users update ...

Added to KEV: Feb 12, 2026
CVE-2025-40536
KEV EPSS 69.1% 8.1

SolarWinds Web Help Desk contains a security control bypass vulnerability that allows unauthenticated attackers to access restricted functionality. Th...

Added to KEV: Feb 12, 2026
CVE-2026-21513
KEV EPSS 3.8% 8.8

This vulnerability in the MSHTML Framework allows attackers to bypass security protections remotely, potentially enabling unauthorized access or code ...

Added to KEV: Feb 10, 2026
CVE-2026-21514
KEV EPSS 2.5% 7.8

This vulnerability in Microsoft Office Word allows attackers to bypass local security features by manipulating untrusted inputs. It affects users runn...

Added to KEV: Feb 10, 2026
CVE-2026-21533
KEV EPSS 2.1% 7.8

This vulnerability allows an authorized attacker with valid Remote Desktop credentials to elevate privileges on a Windows system. It affects Windows s...

Added to KEV: Feb 10, 2026
CVE-2026-21510
KEV EPSS 5.8% 8.8

A protection mechanism failure in Windows Shell allows attackers to bypass security features over a network, potentially enabling unauthorized access ...

Added to KEV: Feb 10, 2026
CVE-2025-11953
KEV EPSS 8.4% 9.8

CVE-2025-11953 is a critical OS command injection vulnerability in the React Native Community CLI's Metro Development Server. Unauthenticated attacker...

Added to KEV: Feb 5, 2026
CVE-2026-24423
KEV EPSS 9.2% 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on SmarterMail servers by pointing them to maliciou...

Added to KEV: Feb 5, 2026
CVE-2025-64328
KEV EPSS 20.6% 7.2

FreePBX Endpoint Manager's filestore module contains a post-authentication command injection vulnerability in the SSH test connection function. Authen...

Added to KEV: Feb 3, 2026
CVE-2025-40551
KEV EPSS 77.7% 9.8

SolarWinds Web Help Desk has an unauthenticated remote code execution vulnerability via untrusted data deserialization. Attackers can execute arbitrar...

Added to KEV: Feb 3, 2026
CVE-2021-39935
KEV EPSS 50.5% 6.8

This vulnerability allows unauthorized external users to perform Server Side Request Forgery (SSRF) attacks through GitLab's CI Lint API. Attackers ca...

Added to KEV: Feb 3, 2026
CVE-2026-1281
KEV EPSS 54.3% 9.8

CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to execute arb...

Added to KEV: Jan 29, 2026
CVE-2026-24858
KEV EPSS 3.4% 9.8

This authentication bypass vulnerability allows attackers with a FortiCloud account and registered device to log into other organizations' Fortinet de...

Added to KEV: Jan 27, 2026
CVE-2026-21509
KEV EPSS 13.4% 7.8

This vulnerability in Microsoft Office allows an attacker to bypass local security features by manipulating untrusted inputs. It affects users running...

Added to KEV: Jan 26, 2026
CVE-2026-24061
KEV EPSS 83.9% 9.8

This vulnerability in GNU Inetutils telnetd allows remote attackers to bypass authentication by setting the USER environment variable to '-f root'. Th...

Added to KEV: Jan 26, 2026
CVE-2026-23760
KEV EPSS 55.5% 9.8

CVE-2026-23760 is an authentication bypass vulnerability in SmarterMail's password reset API that allows unauthenticated attackers to reset administra...

Added to KEV: Jan 26, 2026
CVE-2025-52691
KEV EPSS 82.7% 10.0

This critical vulnerability allows unauthenticated attackers to upload arbitrary files to any location on vulnerable SmarterMail servers, potentially ...

Added to KEV: Jan 26, 2026
CVE-2025-54313
KEV EPSS 4.6% 7.5

This CVE describes a supply chain compromise where malicious versions of eslint-config-prettier contain embedded malware. Installing affected package ...

Added to KEV: Jan 22, 2026
CVE-2025-34026
KEV EPSS 58.5% 7.5

This CVE describes an authentication bypass vulnerability in the Versa Concerto SD-WAN orchestration platform's Traefik reverse proxy configuration. A...

Added to KEV: Jan 22, 2026
CVE-2025-68645
KEV EPSS 29.3% 8.8

An unauthenticated remote attacker can exploit this Local File Inclusion vulnerability in Zimbra Collaboration's Webmail Classic UI to read arbitrary ...

Added to KEV: Jan 22, 2026
CVE-2025-31125
KEV EPSS 66% 5.3

Vite development servers configured to expose content to the network can leak sensitive file contents through specific query parameters (?inline&impor...

Added to KEV: Jan 22, 2026
CVE-2026-20045
KEV EPSS 1.1% 8.2

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by ...

Added to KEV: Jan 21, 2026
CVE-2026-20805
KEV EPSS 8.2% 5.5

This vulnerability in Desktop Windows Manager allows an authorized attacker with local access to disclose sensitive information from the system. It af...

Added to KEV: Jan 13, 2026
CVE-2025-8110
KEV EPSS 22% 8.8

CVE-2025-8110 is a path traversal vulnerability in Gogs' PutContents API that allows improper symbolic link handling, enabling authenticated attackers...

Added to KEV: Jan 12, 2026
CVE-2025-14847
KEV EPSS 57.7% 7.5

This vulnerability allows unauthenticated clients to read uninitialized heap memory from MongoDB servers by exploiting mismatched length fields in Zli...

Added to KEV: Dec 29, 2025
CVE-2023-52163
KEV EPSS 69.2% 8.8

This vulnerability allows remote attackers to execute arbitrary commands on Digiever DS-2105 Pro devices through command injection in the time_tzsetup...

Added to KEV: Dec 22, 2025
CVE-2025-14733
KEV EPSS 43.2% 9.8

A critical out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected s...

Added to KEV: Dec 19, 2025
CVE-2025-40602
KEV EPSS 0.3% 6.6

This CVE describes a local privilege escalation vulnerability in SonicWall SMA1000 appliances where insufficient authorization in the management conso...

Added to KEV: Dec 17, 2025
CVE-2025-59374
KEV EPSS 30.9% 9.8

This CVE describes a supply chain compromise where unauthorized modifications were introduced into certain ASUS Live Update client versions. The modif...

Added to KEV: Dec 17, 2025
CVE-2025-20393
KEV EPSS 4.9% 10.0

An unauthenticated remote attacker can execute arbitrary system commands with root privileges on Cisco Secure Email Gateway and Cisco Secure Email and...

Added to KEV: Dec 17, 2025
CVE-2025-14611
KEV EPSS 57.4% 9.8

This vulnerability in Gladinet CentreStack and Triofox involves hardcoded AES encryption keys, allowing attackers to decrypt sensitive data and potent...

Added to KEV: Dec 15, 2025
CVE-2025-43529
KEV 8.8

A use-after-free vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code. This affects multip...

Added to KEV: Dec 15, 2025
CVE-2025-14174
KEV EPSS 0.7% 8.8

This vulnerability allows remote attackers to perform out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome on m...

Added to KEV: Dec 12, 2025
CVE-2025-6218
KEV EPSS 5.8% 7.8

This vulnerability in WinRAR allows attackers to execute arbitrary code by tricking users into opening malicious archive files containing specially cr...

Added to KEV: Dec 9, 2025
CVE-2025-66644
KEV EPSS 3.1% 7.2

This CVE describes a command injection vulnerability in Array Networks ArrayOS AG VPN appliances. Attackers can execute arbitrary commands on affected...

Added to KEV: Dec 8, 2025
CVE-2025-55182
KEV EPSS 60.9% 10.0

A critical pre-authentication remote code execution vulnerability exists in React Server Components where unsafe deserialization of HTTP payloads allo...

Added to KEV: Dec 5, 2025
CVE-2025-48633
KEV EPSS 0.2% 5.5

This vulnerability in Android's DevicePolicyManagerService allows an attacker to add a Device Owner after device provisioning due to a logic error. Th...

Added to KEV: Dec 2, 2025
CVE-2025-48572
KEV EPSS 0.3% 7.8

This Android vulnerability allows malicious apps to launch activities from the background without proper permissions, enabling local privilege escalat...

Added to KEV: Dec 2, 2025
CVE-2025-61757
KEV EPSS 82.2% 9.8

This critical vulnerability in Oracle Identity Manager allows unauthenticated attackers to remotely compromise the system via HTTP requests, leading t...

Added to KEV: Nov 21, 2025
CVE-2025-13223
KEV EPSS 1.3% 8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Added to KEV: Nov 19, 2025
CVE-2025-58034
KEV EPSS 53% 7.2

This OS command injection vulnerability in Fortinet FortiWeb web application firewalls allows authenticated attackers to execute arbitrary commands on...

Added to KEV: Nov 18, 2025
CVE-2025-64446
KEV EPSS 89% 9.8

A relative path traversal vulnerability in Fortinet FortiWeb web application firewalls allows attackers to execute administrative commands via crafted...

Added to KEV: Nov 14, 2025
CVE-2025-9242
KEV EPSS 61.6% 9.8

An out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected systems. ...

Added to KEV: Nov 12, 2025
CVE-2025-62215
KEV EPSS 0.6% 7.0

This Windows Kernel race condition vulnerability allows authenticated local attackers to escalate privileges by exploiting improper synchronization of...

Added to KEV: Nov 12, 2025
CVE-2025-48703
KEV EPSS 64.3% 9.0

CVE-2025-48703 allows unauthenticated attackers to execute arbitrary commands on CWP (Control Web Panel) servers by injecting shell metacharacters int...

Added to KEV: Nov 4, 2025
CVE-2025-11371
KEV EPSS 68.2% 7.5

An unauthenticated Local File Inclusion vulnerability in Gladinet CentreStack and TrioFox allows attackers to read sensitive system files without cred...

Added to KEV: Nov 4, 2025
CVE-2025-41244
KEV EPSS 1% 7.8

This CVE describes a local privilege escalation vulnerability in VMware Aria Operations and VMware Tools. A malicious local user with non-administrati...

Added to KEV: Oct 30, 2025

What is the CISA KEV Catalog?

The CISA Known Exploited Vulnerabilities (KEV) catalog is a curated list maintained by the Cybersecurity and Infrastructure Security Agency (CISA). Every CVE in this catalog has been confirmed to be actively exploited by threat actors in real-world attacks.

Binding Operational Directive 22-01 requires all US federal agencies to remediate KEV vulnerabilities within specified timeframes. While non-federal organizations are not legally bound, CISA strongly recommends all organizations prioritize KEV entries for immediate patching.

Why KEV matters more than CVSS alone: A vulnerability with a "medium" CVSS score that appears in the KEV catalog is objectively more dangerous than a "critical" CVSS vulnerability that has never been exploited. KEV represents real, confirmed threat activity — not theoretical risk assessments.

Get Instant KEV Alerts

Be the first to know when a CVE affecting your systems gets added to CISA's KEV catalog.

Start Monitoring Free