CISA KEV — Live Table
Sortable, filterable snapshot of CISA's Known Exploited Vulnerabilities catalog — the CVEs U.S. federal agencies must patch on a deadline.
The CISA Known Exploited Vulnerabilities (KEV) catalog is the closest thing the industry has to a public "patch this now" list. Under Binding Operational Directive 22-01, U.S. federal civilian agencies must remediate every CVE on the list by the published due date, and the same list has become the de facto priority queue for private-sector security and change teams too. This tool renders a compact, sortable snapshot of the catalog so a change manager can scan it in seconds: click any column header to sort, type in the filter box to narrow by vendor / product / CVE, or flip the ransomware-use toggle to show only the entries CISA has flagged as tied to active ransomware campaigns. The underlying data comes from CISA's public JSON feed; the snapshot bundled with this page refreshes nightly. For the authoritative, up-to-the-minute list, use the CISA link at the bottom. Nothing you type here is sent to a server — filtering and sorting all happens in the browser.
| CVE | Vendor | Product | Date added | Due date | Notes |
|---|---|---|---|---|---|
| CVE-2026-85046 | Chromium V8 | 2026-09-04 | 2026-09-18 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | |
| CVE-2026-83549 | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 | SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. |
| CVE-2026-83548 | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 | SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. |
| CVE-2026-9586 | Sangoma | Switchvox | 2026-09-02 | 2026-09-05 | Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. |
| CVE-2026-82329 | JFrog | Artifactory | 2026-09-02 | 2026-09-05 | JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. |
| CVE-2026-49869 | Kestra | Kestra OSS | 2026-09-02 | 2026-09-05 | Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. |
| CVE-2026-48710 | Kludex | Starlette | 2026-09-02 | 2026-09-16 | Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271. |
| CVE-2026-59822 | BerriAI | LiteLLM | 2026-09-02 | 2026-09-16 | BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. |
| CVE-2026-81578 | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 | PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. |
| CVE-2026-82078 | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 | PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. |
| CVE-2026-66384 | JFrog | Artifactory | 2026-08-27 | 2026-09-10 | JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. |
| CVE-2026-53362 | Linux | Kernel | 2026-08-27 | 2026-08-30 | Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. |
| CVE-2023-49105 | ownCloud | ownCloud | 2026-08-27 | 2026-08-30 | ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. |
| CVE-2019-1068 | Microsoft | SQL Server | 2026-08-26 | 2026-08-29 | Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. |
| CVE-2026-8452 | Citrix | NetScaler ADC and NetScaler Gateway | 2026-08-26 | 2026-08-29 | Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. |
| CVE-2022-0995 | Linux | Kernel | 2026-08-26 | 2026-09-09 | Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. |
| CVE-2015-5287 | Red Hat | Automatic Bug Reporting Tool | 2026-08-26 | 2026-09-09 | Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. |
| CVE-2015-3246 | Red Hat | Libuser | 2026-08-26 | 2026-09-09 | Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. |
| CVE-2021-23758 | Ajax.NET Professional | Ajax.NET Professional | 2026-08-26 | 2026-09-09 | Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. |
| CVE-2026-60004 | Gitea | Gitea | 2026-08-25 | 2026-08-28 | Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. |
Source: CISA Known Exploited Vulnerabilities Catalog. Snapshot generated 2026-09-05T08:02:16Z.
About this tool
The KEV catalog is most useful when it shortens a practical question: which entries require an owner to determine whether the organization is exposed? This view makes the public catalog easier to sort and filter during triage. Search by vendor, product, or catalog field, then move relevant entries into the workflow that connects findings to assets, owners, and due dates.
A catalog entry signals known exploitation, not automatic impact. Start with the affected product and vulnerability details, validate installed versions and exposure paths, and check the required action against local policy. The date belongs to the catalog record, not a disclosure or exploitation-start date. When a deadline applies, track the organization's response and any accepted exception outside this table.
How to read the output
- Filter first, then carefully validate each candidate against owned assets.
- Use the required action as a starting point for remediation planning.
- Separate catalog status from internal evidence of exposure or exploitation.
- Assign exceptions and completion evidence in the vulnerability management system.
What this does not tell you
- KEV catalog dates describe CISA catalog activity and do not establish the vulnerability's disclosure or exploitation start date.
- The catalog cannot identify which assets, versions, internet exposures, or compensating controls exist in a specific environment.
- CISA entries are a high-priority input, but organizations still need their own threat, business, and change context.
Data sources
Free to use, no account required, and nothing you enter is transmitted to this site — the tool runs entirely in your browser.