CISA KEV catalog
Known exploited vulnerabilities
Not "could be exploited". Exploited. In the wild, right now.
Every CVE in the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog: what is affected, what CISA requires you to do and by when, whether ransomware crews use it, and the weakness behind it.
1,731 CVEs · 283 vendors · 361 used in ransomware · catalog 2026.10.01, released October 1, 2026
Patch these first361 known exploited vulnerabilities used by ransomwareThe entries CISA marks as known to be used in ransomware campaigns.
Added most recently
- CVE-2026-104286Fortinet FortiMail Path Traversal Vulnerability · added October 1, 2026
- CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability · added September 30, 2026
- CVE-2026-86950Apple Multiple Products Out-of-Bounds Write Vulnerability · added September 29, 2026
- CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability · added September 27, 2026
- CVE-2026-88771Citrix NetScaler Improper Input Validation Vulnerability · added September 27, 2026
- CVE-2026-87902WordPress Core Remote File Inclusion Vulnerability · added September 25, 2026
- CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability · added September 25, 2026
- CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability · added September 25, 2026
- CVE-2026-71362Adobe Commerce and Magento Incorrect Authorization Vulnerability · added September 24, 2026
- CVE-2026-5430WSO2 Multiple Products Path Traversal Vulnerability · added September 24, 2026
- CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability · added September 22, 2026
- CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation Vulnerability · added September 22, 2026
- CVE-2026-93616Check Point Multiple Products Path Traversal Vulnerability · added September 22, 2026
- CVE-2026-85102Check Point Multiple Products Improper Certificate Validation Vulnerability · added September 22, 2026
- CVE-2026-7273Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability · added September 21, 2026
- CVE-2026-53266Linux Kernel Out-of-Bounds Write Vulnerability · added September 18, 2026
- CVE-2025-39964Linux Kernel Race Condition Vulnerability · added September 18, 2026
- CVE-2025-39682Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability · added September 18, 2026
- CVE-2026-87886Acronis Backup Incorrect Default Permissions Vulnerability · added September 16, 2026
- CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability · added September 16, 2026
- CVE-2026-58704Google Pixel Improper Authorization Vulnerability · added September 16, 2026
- CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability · added September 14, 2026
- CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability · added September 11, 2026
- CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability · added September 11, 2026
- CVE-2026-42018JFrog Artifactory Improper Authentication Vulnerability · added September 11, 2026
- CVE-2026-42016JFrog Artifactory Incorrect Authorization Vulnerability · added September 11, 2026
- CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability · added September 10, 2026
- CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function Vulnerability · added September 10, 2026
- CVE-2026-87491Google Chromium V8 Out of Bounds Write Vulnerability · added September 9, 2026
- CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability · added September 9, 2026
- CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability · added September 9, 2026
- CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability · added September 9, 2026
- CVE-2026-86218N-able N-central Static Code Injection Vulnerability · added September 8, 2026
- CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow Vulnerability · added September 8, 2026
- CVE-2026-81963Microsoft Windows Link Following Vulnerability · added September 8, 2026
- CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability · added September 8, 2026
- CVE-2026-85046Google Chromium V8 Type Confusion Vulnerability · added September 4, 2026
- CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection Vulnerability · added September 2, 2026
- CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability · added September 2, 2026
- CVE-2026-82329JFrog Artifactory Improper Authentication Vulnerability · added September 2, 2026
By vendor
- 7-Zip1
- Accellion4
- Acclaim Systems1
- Acronis2
- Adminer1
- Adobe82
- Advantive2
- Ajax.NET Professional1
- Alcatel1
- Amcrest1
- AMI1
- Android17
- Apache40
- Apple95
- Aquasecurity1
- Arcadyan1
- Arcserve1
- Arista3
- Arm9
- Array Networks 2
- Artifex1
- ASUS3
- Atlassian13
- Audinate1
- Aviatrix2
- Balbooa1
- Barracuda Networks1
- BerriAI3
- BeyondTrust3
- BQE1
- Broadcom5
- Cacti1
- ChakraCore1
- Check Point5
- Checkbox1
- Cisco100
- Citrix26
- Cleo2
- Code Aurora1
- Commvault2
- ConnectWise4
- Craft CMS4
- Crestron1
- CrushFTP3
- CWP2
- CyberPersons2
- D-Link26
- D-Link and TRENDnet1
- Daemon1
- Dahua2
- Dasan2
- Dassault Systèmes3
- DD-WRT1
- Dell2
- Delta Electronics1
- Digiever1
- Docker1
- dotCMS1
- DotNetNuke (DNN)3
- DrayTek5
- Drupal5
- Edimax1
- Elastic3
- Embedthis1
- Erlang1
- Exim5
- EyesOfNetwork2
- F58
- FatPipe1
- ForgeRock1
- Fortinet31
- Fortra4
- FreeType1
- Fuel CMS1
- FXC1
- GeoVision2
- GIGABYTE4
- Git1
- Gitea1
- GitLab5
- Gladinet4
- GNU5
- Gogs1
- Google75
- Grafana Labs2
- Grandstream1
- Hewlett Packard (HP)2
- Hewlett Packard Enterprise (HPE)1
- Hikvision2
- Hitachi Vantara2
- IBM8
- iCagenda1
- IETF2
- IGEL1
- Ignite Realtime1
- ImageMagick3
- InduSoft1
- Intel2
- Ivanti35
- Jenkins6
- JetBrains4
- JFrog4
- Joomla!1
- Joomlack1
- JoomShaper1
- JQuery1
- Juniper8
- Justice AV Solutions1
- Kaseya3
- Kentico4
- Kestra1
- Kingsoft1
- Kludex1
- KNX Association1
- Langflow5
- Lantronix1
- Laravel3
- LG1
- Libraesva1
- Liferay1
- Linux31
- LiteSpeed2
- Looking Glass1
- Marimo1
- McAfee1
- MDaemon1
- MediaTek1
- Meta1
- Meta Platforms3
- Metabase2
- Micro Focus2
- Microsoft389
- MikroTik5
- MinIO2
- Mirasvit1
- Mitel7
- MLflow1
- MongoDB2
- Motex1
- Mozilla13
- N-able5
- n8n1
- Nagios4
- NAKIVO1
- NETGEAR8
- Netis1
- Netwrix1
- NextGen Healthcare1
- Nice1
- North Grid1
- Nostromo1
- Notepad++1
- Novi Survey1
- Npm package1
- NUUO2
- Nx1
- October CMS1
- Omnissa1
- OpenBSD1
- OpenPLC2
- OpenSSL1
- Oracle46
- OSGeo3
- ownCloud2
- Paessler2
- Palo Alto Networks15
- PaperCut5
- PEAR2
- Perl1
- PHP3
- PHP Group1
- phpMyAdmin1
- PHPUnit1
- Pi-hole1
- PlaySMS1
- Plex1
- Prettier1
- Primetek1
- Progress9
- ProjectSend1
- PTC1
- PTZOptics2
- Pulse Secure1
- Qlik3
- QNAP11
- QNAP Systems1
- Qualcomm12
- Qualitia1
- Quest2
- Rails3
- RARLAB5
- Ray-Project1
- rConfig1
- React Native Community1
- Realtek3
- Red Hat9
- Redis1
- Rejetto2
- Reolink2
- reviewdog1
- Rockwell1
- Roundcube11
- Ruckus Wireless1
- SaltStack3
- Samba1
- Samsung15
- Sangoma4
- SAP14
- Schneider Electric1
- ScienceLogic1
- ServiceNow2
- Siemens1
- Sierra Wireless1
- SIMalliance1
- SimpleHelp 4
- Sitecore4
- SKYSEA1
- Smartbedded1
- SmarterTools3
- SolarView1
- SolarWinds11
- Soliton Systems K.K1
- Sonatype2
- SonicWall19
- Sophos7
- Splunk1
- Spreadsheet::ParseExcel1
- Srimax1
- Sudo2
- SugarCRM1
- Sumavision1
- Sunhillo1
- Symantec1
- Synacor19
- SysAid3
- TanStack1
- TeamT51
- TeamViewer1
- Teclib1
- TeleMessage3
- Telerik2
- Tenda3
- TerraMaster1
- ThinkPHP2
- TIBCO2
- tj-actions1
- TP-Link6
- Treck TCP/IP stack1
- Trend Micro12
- Trihedral1
- Trimble1
- TrueConf3
- TVT1
- Twilio1
- Ubiquiti4
- Unitronics1
- Unraid2
- vBulletin2
- Veeam4
- Veritas3
- Versa2
- Vite1
- VMware26
- VMware Tanzu3
- WatchGuard4
- Wazuh1
- WebKitGTK1
- Webmin1
- WebPros1
- WebRTC1
- Widget Factory1
- Wing FTP Server2
- WordPress6
- WSO22
- XStream1
- XWiki1
- Yealink1
- Yiiframework1
- Zabbix2
- ZK Framework1
- ZKTeco1
- Zoho9
- Zyxel13
Source: CISA Known Exploited Vulnerabilities Catalog (public domain), catalog version 2026.10.01.