CISA Known Exploited Vulnerabilities
Recently added to the CISA KEV catalog
29 CVEs entered the KEV catalog in the last 30 days. Each row carries the date CISA added it, the due date it set, and the CVSS and EPSS scores as they stand today.
Added September 4, 20261
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 0.5 % | September 18, 2026 |
Added September 2, 20266
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 6.5 | 0.0 % | September 16, 2026 |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | — | 0.2 % | September 16, 2026 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | 9.8 | 0.4 % | September 5, 2026 |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 10 | 0.3 % | September 5, 2026 |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | 7.8 | 0.9 % | September 5, 2026 |
| CVE-2026-9586 | Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | — | 0.4 % | September 5, 2026 |
Added August 31, 20262
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | — | 0.4 % | September 14, 2026 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | — | 0.5 % | September 14, 2026 |
Added August 27, 20262
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | — | 0.2 % | August 30, 2026 |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 5.3 | 0.3 % | September 10, 2026 |
Added August 26, 20264
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | 8.8 | 41.6 % | August 29, 2026 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 9.8 | 87.8 % | September 9, 2026 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | 7.8 | 20.5 % | September 9, 2026 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 9.8 | 0.4 % | August 29, 2026 |
Added August 25, 20261
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-60004 | Gitea Code Injection Vulnerability | 9.8 | 82.4 % | August 28, 2026 |
Added August 24, 20261
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 10 | 0.0 % | August 27, 2026 |
Added August 21, 20262
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-69836 | Microsoft Entra ID Deserialization of Untrusted Data Vulnerability | 10 | 1.4 % | August 24, 2026 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 8.9 | 0.5 % | August 24, 2026 |
Added August 20, 20262
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | 9.8 | 0.8 % | August 23, 2026 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | 9 | 1.0 % | September 3, 2026 |
Added August 19, 20261
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | 9.3 | 1.1 % | September 2, 2026 |
Added August 18, 20264
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 9.8 | 0.1 % | August 21, 2026 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | 9.1 | 0.7 % | August 21, 2026 |
| CVE-2026-59310 | vCenter directory-traversal vulnerability | 9.8 | 1.1 % | August 21, 2026 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | 7.1 | 0.3 % | August 21, 2026 |
Added August 11, 20263
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 8.6 | 1.0 % | August 14, 2026 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 7 | 0.4 % | August 25, 2026 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | 10 | 0.7 % | August 14, 2026 |