CISA KEV
Known exploited vulnerabilities, daily
Every flaw CISA adds to its Known Exploited Vulnerabilities catalog, grouped by day, with the vendor fix and federal deadline. Refreshed from CISA's official feed on every deploy.
added in the last 30 days
of those with known ransomware use
entries in the full catalog
Most-listed vendors, 30 days
Citrix (3)
Microsoft (3)
MikroTik (3)
Linux (3)
Google (3)
Cisco (3)
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is the US Cybersecurity and Infrastructure Security Agency's list of software flaws with reliable evidence of exploitation in the wild. Under Binding Operational Directive 22-01, US federal civilian agencies must fix each listed flaw by its due date — usually within three weeks, sometimes days. Everyone else can use it as a free, evidence-based patch priority list: if a flaw is on KEV, attackers are already using it.
Source: CISA KEV catalog · BOD 22-01 · Catalog version 2026.09.27
Daily additions