Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,730 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
Need it fresh, filtered or via API?These pages are a free snapshot, last updated 2026-10-01.
- Kevscope API $5 pack $5 for 2,000 calls, never expires: patch-priority verdicts for up to 20 CVEs per call from today's KEV, EPSS, CVSS and SSVC data, by REST API or MCP. Pay by card, your API key is on screen the moment checkout ends; no account, no subscription.
- Exploited Vulnerabilities Brief: Weekly Edition $9/month: a fresh KEV + EPSS brief every Monday (PDF + CSVs): new exploited CVEs, what to patch first, upcoming CISA deadlines.
- Kevscope CVE priority API 200 free calls a day, $5 for 2,000 calls (no expiry), or $19/month for 10,000: returns a patch-priority verdict for up to 20 CVEs per call with the evidence (KEV, EPSS, CVSS, CISA SSVC), most urgent first, by API or MCP.
- Exploited Vulnerabilities Brief (September 2026) $15: this month's KEV additions ranked by EPSS, ransomware use and due date, as a one-off report.
- All Three Monday Briefs: Rates, Recalls + Exploited Vulns $25/month: all three weekly briefs (Treasury/BLS rates & macro, NHTSA recalls, CISA KEV/EPSS) for $25/month instead of $37.
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | 2026-09-30 | — | |
| CVE-2026-86950 | Apple Multiple Products | 2026-09-29 | 1.2% | |
| CVE-2026-88772 | Citrix NetScaler | 2026-09-27 | 1.3% | |
| CVE-2026-88771 | Citrix NetScaler | 2026-09-27 | 1.1% | |
| CVE-2026-87902 | WordPress Core | 2026-09-25 | 19.8% | |
| CVE-2026-67279 | MikroTik RouterOS | 2026-09-25 | 1.0% | |
| CVE-2026-65660 | Microsoft SharePoint | 2026-09-25 | 2.1% | |
| CVE-2026-71362 | Adobe Commerce and Magento | 2026-09-24 | 87.5% | |
| CVE-2026-5430 | WSO2 Multiple Products | 2026-09-24 | 0.6% | |
| CVE-2026-94127 | F5 BIG-IP APM | 2026-09-22 | 2.2% | |
| CVE-2026-93952 | Arista VeloCloud Orchestrator | 2026-09-22 | 1.1% | |
| CVE-2026-93616 | Check Point Multiple Products | 2026-09-22 | 19.7% | |
| CVE-2026-85102 | Check Point Multiple Products | 2026-09-22 | 7.5% | |
| CVE-2026-7273 | Zyxel GS1900 Series Switches | 2026-09-21 | 2.5% | |
| CVE-2026-53266 | Linux Kernel | 2026-09-18 | 0.6% | |
| CVE-2025-39964 | Linux Kernel | 2026-09-18 | 1.0% | |
| CVE-2025-39682 | Linux Kernel | 2026-09-18 | 2.9% | |
| CVE-2026-87886 | Acronis Backup | 2026-09-16 | 0.2% | |
| CVE-2026-76460 | Cisco Identity Services Engine | 2026-09-16 | 14.0% | |
| CVE-2026-58704 | Google Pixel | 2026-09-16 | 0.6% | |
| CVE-2026-76461 | Cisco Secure Email Gateway | 2026-09-14 | 28.3% | |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition | 2026-09-11 | 91.4% | |
| CVE-2026-84869 | ConnectWise ScreenConnect | 2026-09-11 | 0.9% | |
| CVE-2026-42018 | JFrog Artifactory | 2026-09-11 | 9.8% | |
| CVE-2026-42016 | JFrog Artifactory | 2026-09-11 | 8.6% | |
| CVE-2026-86060 | MikroTik RouterOS | 2026-09-10 | 1.8% | |
| CVE-2026-67277 | MikroTik RouterOS | 2026-09-10 | 1.6% | |
| CVE-2026-87491 | Google Chromium V8 | 2026-09-09 | 3.1% | |
| CVE-2026-20079 | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 2026-09-09 | 88.2% | |
| CVE-2026-19490 | Citrix NetScaler | 2026-09-09 | 7.0% | |
| CVE-2025-25249 | Fortinet Multiple Products | 2026-09-09 | 3.9% | |
| CVE-2026-86218 | N-able N-central | 2026-09-08 | 12.9% | |
| CVE-2026-85880 | Microsoft Windows | 2026-09-08 | 3.6% | |
| CVE-2026-81963 | Microsoft Windows | 2026-09-08 | 0.4% | |
| CVE-2026-75650 | Adobe Commerce and Magento | 2026-09-08 | 3.9% | |
| CVE-2026-85046 | Google Chromium V8 | 2026-09-04 | 48.9% | |
| CVE-2026-9586 | Sangoma Switchvox | 2026-09-02 | 19.0% | |
| CVE-2026-83549 | SonicWall SMA1000 Appliances | 2026-09-02 | 10.8% | |
| CVE-2026-83548 | SonicWall SMA1000 Appliances | 2026-09-02 | 8.8% | |
| CVE-2026-82329 | JFrog Artifactory | 2026-09-02 | 14.1% | |
| CVE-2026-59822 | BerriAI LiteLLM | 2026-09-02 | 0.8% | |
| CVE-2026-49869 | Kestra Kestra OSS | 2026-09-02 | 2.1% | |
| CVE-2026-48710 | Kludex Starlette | 2026-09-02 | 7.1% | |
| CVE-2026-82078 | PaperCut NG/MF | 2026-08-31 | 61.4% | |
| CVE-2026-81578 | PaperCut NG/MF | 2026-08-31 | 85.2% | |
| CVE-2026-66384 | JFrog Artifactory | 2026-08-27 | 0.7% | |
| CVE-2026-53362 | Linux Kernel | 2026-08-27 | 0.7% | |
| CVE-2023-49105 | ownCloud ownCloud | 2026-08-27 | 42.9% | |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | 2026-08-26 | 1.0% | |
| CVE-2022-0995 | Linux Kernel | 2026-08-26 | 8.8% | |
| CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | 2026-08-26 | 82.6% | |
| CVE-2019-1068 | Microsoft SQL Server | 2026-08-26 | 57.0% | |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | 2026-08-26 | 5.0% | |
| CVE-2015-3246 | Red Hat Libuser | 2026-08-26 | 8.8% | |
| CVE-2026-60004 | Gitea Gitea | 2026-08-25 | 24.0% | |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | 2026-08-24 | 70.9% | |
| CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | 2026-08-21 | 11.7% | |
| CVE-2026-72530 | TrueConf Server | 2026-08-20 | 1.7% | |
| CVE-2026-72529 | TrueConf Server | 2026-08-20 | 1.5% | |
| CVE-2026-64849 | MLflow MLflow | 2026-08-19 | 9.8% | |
| CVE-2026-65400 | Apple macOS | 2026-08-18 | 1.7% | |
| CVE-2026-59310 | Broadcom VMware vCenter | 2026-08-18 | 2.6% | known |
| CVE-2026-55040 | Microsoft SharePoint | 2026-08-18 | 17.5% | |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | 2026-08-18 | 1.6% | |
| CVE-2025-62593 | Ray-Project Ray | 2026-08-17 | 62.5% | |
| CVE-2026-72898 | Metabase Metabase | 2026-08-11 | 19.0% | |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | 2026-08-11 | 0.3% | |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | 2026-08-11 | 1.0% | |
| CVE-2026-8037 | Progress LoadMaster | 2026-08-07 | 77.4% | |
| CVE-2026-63077 | JetBrains TeamCity | 2026-08-05 | 89.6% | known |
| CVE-2026-9198 | IBM Langflow | 2026-08-04 | 28.7% | |
| CVE-2026-34486 | Apache Tomcat | 2026-08-04 | 6.6% | |
| CVE-2026-18556 | N-able N-central | 2026-08-04 | 7.9% | |
| CVE-2026-18577 | N-able N-central | 2026-08-03 | 14.6% | |
| CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | 2026-07-29 | 35.1% | known |
| CVE-2026-16812 | Arista VeloCloud Orchestrator | 2026-07-27 | 1.0% | |
| CVE-2025-68686 | Fortinet FortiOS | 2026-07-27 | 29.6% | |
| CVE-2026-50522 | Microsoft SharePoint | 2026-07-22 | 3.0% | |
| CVE-2026-16232 | Check Point SmartConsole | 2026-07-22 | 78.0% | |
| CVE-2026-63030 | WordPress Core | 2026-07-21 | 10.1% | |
| CVE-2026-60137 | WordPress Core | 2026-07-21 | 5.9% | |
| CVE-2026-0770 | Langflow Langflow | 2026-07-21 | 63.8% | |
| CVE-2021-27137 | DD-WRT DD-WRT | 2026-07-21 | 4.0% | |
| CVE-2026-58644 | Microsoft SharePoint | 2026-07-16 | 15.9% | |
| CVE-2026-39808 | Fortinet FortiSandbox | 2026-07-16 | 47.4% | |
| CVE-2026-25089 | Fortinet FortiSandbox | 2026-07-16 | 76.1% | |
| CVE-2026-46817 | Oracle E-Business Suite | 2026-07-15 | 0.8% | |
| CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 | 2026-07-15 | 1.3% | |
| CVE-2026-56164 | Microsoft SharePoint Server | 2026-07-14 | 1.0% | |
| CVE-2026-56155 | Microsoft Active Directory Federation Services | 2026-07-14 | 0.3% | |
| CVE-2026-15410 | SonicWall SMA1000 Appliances | 2026-07-14 | 11.8% | known |
| CVE-2026-15409 | SonicWall SMA1000 Appliances | 2026-07-14 | 6.8% | known |
| CVE-2008-4128 | Cisco IOS | 2026-07-13 | 33.9% | |
| CVE-2026-56291 | Balbooa Forms | 2026-07-10 | 14.9% | |
| CVE-2026-48939 | iCagenda iCagenda | 2026-07-10 | 20.1% | |
| CVE-2026-56290 | Joomlack Page Builder | 2026-07-07 | 30.9% | |
| CVE-2026-55255 | Langflow Langflow | 2026-07-07 | 0.9% | |
| CVE-2026-48908 | JoomShaper SP Page Builder | 2026-07-07 | 88.5% | |
| CVE-2026-48282 | Adobe ColdFusion | 2026-07-07 | 42.4% | |
| CVE-2026-45659 | Microsoft SharePoint Server | 2026-07-01 | 2.7% | known |
| CVE-2026-48558 | SimpleHelp SimpleHelp | 2026-06-29 | 5.7% | |
| CVE-2026-20230 | Cisco Unified Communications Manager | 2026-06-25 | 88.2% | |
| CVE-2026-12569 | PTC Windchill and FlexPLM | 2026-06-25 | 46.0% | known |
| CVE-2026-34910 | Ubiquiti UniFi OS | 2026-06-23 | 45.8% | |
| CVE-2026-34909 | Ubiquiti UniFi OS | 2026-06-23 | 1.8% | |
| CVE-2026-34908 | Ubiquiti UniFi OS | 2026-06-23 | 15.2% | |
| CVE-2025-67038 | Lantronix EDS5000 | 2026-06-23 | 19.3% | |
| CVE-2026-20253 | Splunk Enterprise | 2026-06-18 | 96.9% | |
| CVE-2026-48907 | Widget Factory Joomla Content Editor | 2026-06-16 | 16.2% | |
| CVE-2026-54420 | LiteSpeed cPanel Plugin | 2026-06-15 | 0.8% | |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | 2026-06-15 | 28.2% | |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | 2026-06-12 | 9.4% | known |
| CVE-2026-10520 | Ivanti Sentry | 2026-06-11 | 99.9% | |
| CVE-2026-7473 | Arista Extensible Operating System | 2026-06-09 | 0.6% | |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | 2026-06-09 | 25.3% | |
| CVE-2026-11645 | Google Chromium V8 | 2026-06-09 | 2.2% | |
| CVE-2026-50751 | Check Point Security Gateway | 2026-06-08 | 6.3% | known |
| CVE-2026-42271 | BerriAI LiteLLM | 2026-06-08 | 92.6% | |
| CVE-2026-28318 | SolarWinds Serv-U | 2026-06-05 | 1.9% | |
| CVE-2026-45247 | Mirasvit Mirasvit Full Page Cache Warmer | 2026-06-03 | 2.1% | |
| CVE-2025-48595 | Android Framework | 2026-06-02 | 1.7% | |
| CVE-2022-0492 | Linux Kernel | 2026-06-02 | 5.5% | |
| CVE-2024-21182 | Oracle WebLogic Server | 2026-06-01 | 74.2% | |
| CVE-2026-0257 | Palo Alto Networks PAN-OS | 2026-05-29 | 96.4% | known |
| CVE-2026-8398 | Daemon Daemon Tools Lite | 2026-05-27 | 1.0% | |
| CVE-2026-48027 | Nx Nx Console | 2026-05-27 | 1.3% | known |
| CVE-2026-45321 | TanStack TanStack | 2026-05-27 | 1.1% | known |
| CVE-2026-48172 | LiteSpeed cPanel Plugin | 2026-05-26 | 1.0% | |
| CVE-2026-9082 | Drupal Core | 2026-05-22 | 15.7% | |
| CVE-2026-34926 | Trend Micro Apex One | 2026-05-21 | 0.5% | |
| CVE-2025-34291 | Langflow Langflow | 2026-05-21 | 92.8% | |
| CVE-2026-45498 | Microsoft Defender | 2026-05-20 | 1.3% | |
| CVE-2026-41091 | Microsoft Defender | 2026-05-20 | 0.4% | |
| CVE-2010-0806 | Microsoft Internet Explorer | 2026-05-20 | 82.2% | |
| CVE-2010-0249 | Microsoft Internet Explorer | 2026-05-20 | 91.9% | |
| CVE-2009-3459 | Adobe Acrobat and Reader | 2026-05-20 | 86.6% | |
| CVE-2009-1537 | Microsoft DirectX | 2026-05-20 | 51.2% | |
| CVE-2008-4250 | Microsoft Windows | 2026-05-20 | 98.8% | |
| CVE-2026-42897 | Microsoft Microsoft | 2026-05-15 | 0.5% | |
| CVE-2026-20182 | Cisco Catalyst SD-WAN | 2026-05-14 | 91.5% | |
| CVE-2026-42208 | BerriAI LiteLLM | 2026-05-08 | 5.8% | |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 2026-05-07 | 2.5% | |
| CVE-2026-0300 | Palo Alto Networks PAN-OS | 2026-05-06 | 31.7% | |
| CVE-2026-31431 | Linux Kernel | 2026-05-01 | 3.4% | |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) | 2026-04-30 | 98.5% | known |
| CVE-2026-32202 | Microsoft Windows | 2026-04-28 | 4.9% | |
| CVE-2024-1708 | ConnectWise ScreenConnect | 2026-04-28 | 95.4% | known |
| CVE-2025-29635 | D-Link DIR-823X | 2026-04-24 | 87.9% | |
| CVE-2024-7399 | Samsung MagicINFO 9 Server | 2026-04-24 | 91.9% | |
| CVE-2024-57728 | SimpleHelp SimpleHelp | 2026-04-24 | 64.7% | known |
| CVE-2024-57726 | SimpleHelp SimpleHelp | 2026-04-24 | 66.6% | known |
| CVE-2026-39987 | Marimo Marimo | 2026-04-23 | 37.9% | |
| CVE-2026-33825 | Microsoft Defender | 2026-04-22 | 0.4% | known |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 2026-04-20 | 31.8% | |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 2026-04-20 | 7.1% | |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manger | 2026-04-20 | 25.0% | |
| CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) | 2026-04-20 | 1.7% | |
| CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) | 2026-04-20 | 2.5% | |
| CVE-2025-2749 | Kentico Kentico Xperience | 2026-04-20 | 4.1% | |
| CVE-2024-27199 | JetBrains TeamCity | 2026-04-20 | 100.0% | known |
| CVE-2023-27351 | PaperCut NG/MF | 2026-04-20 | 78.1% | known |
| CVE-2026-34197 | Apache ActiveMQ | 2026-04-16 | 15.5% | |
| CVE-2026-32201 | Microsoft SharePoint Server | 2026-04-14 | 1.0% | |
| CVE-2009-0238 | Microsoft Office | 2026-04-14 | 43.2% | |
| CVE-2026-34621 | Adobe Acrobat and Reader | 2026-04-13 | 2.2% | |
| CVE-2026-21643 | Fortinet FortiClient EMS | 2026-04-13 | 93.7% | |
| CVE-2025-60710 | Microsoft Windows | 2026-04-13 | 4.6% | known |
| CVE-2023-36424 | Microsoft Windows | 2026-04-13 | 12.2% | |
| CVE-2023-21529 | Microsoft Exchange Server | 2026-04-13 | 59.3% | known |
| CVE-2020-9715 | Adobe Acrobat | 2026-04-13 | 48.6% | |
| CVE-2012-1854 | Microsoft Visual Basic for Applications (VBA) | 2026-04-13 | 21.0% | |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) | 2026-04-08 | 98.6% | |
| CVE-2026-35616 | Fortinet FortiClient EMS | 2026-04-06 | 9.1% | |
| CVE-2026-3502 | TrueConf Client | 2026-04-02 | 0.3% | |
| CVE-2026-5281 | Google Dawn | 2026-04-01 | 0.7% | |
| CVE-2026-3055 | Citrix NetScaler | 2026-03-30 | 4.0% | |
| CVE-2025-53521 | F5 BIG-IP | 2026-03-27 | 2.3% | |
| CVE-2026-33634 | Aquasecurity Trivy | 2026-03-26 | 1.7% | |
| CVE-2026-33017 | Langflow Langflow | 2026-03-25 | 24.8% | |
| CVE-2025-54068 | Laravel Livewire | 2026-03-20 | 97.1% | |
| CVE-2025-43520 | Apple Multiple Products | 2026-03-20 | 0.4% | |
| CVE-2025-43510 | Apple Multiple Products | 2026-03-20 | 0.4% | |
| CVE-2025-32432 | Craft CMS Craft CMS | 2026-03-20 | 99.8% | |
| CVE-2025-31277 | Apple Multiple Products | 2026-03-20 | 1.6% | |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) | 2026-03-19 | 42.7% | known |
| CVE-2026-20963 | Microsoft SharePoint | 2026-03-18 | 29.6% | |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) | 2026-03-18 | 19.6% | |
| CVE-2025-47813 | Wing FTP Server Wing FTP Server | 2026-03-16 | 63.1% | |
| CVE-2026-3910 | Google Chromium V8 | 2026-03-13 | 1.0% | |
| CVE-2026-3909 | Google Skia | 2026-03-13 | 0.7% | |
| CVE-2025-68613 | n8n n8n | 2026-03-11 | 99.0% | |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) | 2026-03-09 | 87.9% | |
| CVE-2025-26399 | SolarWinds Web Help Desk | 2026-03-09 | 89.5% | known |
| CVE-2021-22054 | Omnissa Workspace One UEM | 2026-03-09 | 99.7% | |
| CVE-2023-43000 | Apple Multiple Products | 2026-03-05 | 3.9% | |
| CVE-2023-41974 | Apple iOS and iPadOS | 2026-03-05 | 1.9% | |
| CVE-2021-30952 | Apple Multiple Products | 2026-03-05 | 7.0% | |
| CVE-2021-22681 | Rockwell Multiple Products | 2026-03-05 | 63.6% | |
| CVE-2017-7921 | Hikvision Multiple Products | 2026-03-05 | 100.0% | |
| CVE-2026-22719 | Broadcom VMware Aria Operations | 2026-03-03 | 17.7% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.