Known exploited
Every flaw in CISA's catalogue of vulnerabilities exploited in the wild, grouped by the vendor whose product it hit. The most exploited vendors ride the inner orbits, and the core holds one dot for every CVE, newest at the top.
A snapshot of CISA's Known Exploited Vulnerabilities catalogue, embedded in this page. Nothing is fetched: everything runs in this tab.
Vendors in orbit
The catalogue
Choose a vendor from the list or the orrery for its products and CVEs.
- A body is a vendor, sized by its entries. The most exploited ride the inner orbits.
- Ember shows the share of a vendor's entries with known ransomware use.
- A ring marks a vendor with an entry added in the 30 days before this snapshot.
- Each dot in the core is one CVE: newest at the top, the 2021 launch batch at the bottom.
- The outer belt is the long tail, one speck per vendor.
The latest entries
What the catalogue is, and what to do with it
What KEV is
CISA, the US Cybersecurity and Infrastructure Security Agency, keeps the Known Exploited Vulnerabilities catalogue: the flaws it has reliable evidence attackers have exploited in the wild. It opened on 3 Nov 2021, and 0 of the entries listed today date from that first day. This snapshot holds 0, from 0 vendors.
An entry has to clear three bars:
- A CVE ID. The public identifier the rest of the industry uses for the flaw.
- Reliable evidence of exploitation in the wild. Attempted and successful attacks both count. Scanning, security research and a published proof of concept do not.
- A clear action. Usually a vendor update or mitigation; for a product past its end of life, taking it off the network.
Who has to act, and by when
US federal civilian agencies must fix listed flaws by deadlines CISA sets. BOD 22-01 created the catalogue and those deadlines in November 2021. On 10 June 2026 BOD 26-04 revoked it and tied each deadline to four questions: is the asset exposed to the internet, is the flaw in the catalogue, can an attacker automate the exploit, and how much control does it give them? CISA calculates each entry's due date from that table with the data it has: a flaw it sees on exposed assets, automatable and giving total control, gets three days.
For an entry flagged for forensic triage (0 in this snapshot), agencies must also check the affected systems for signs they were already compromised. The newest entries cite BOD 26-04, first cited on . Other organisations are not bound by these deadlines, but CISA strongly recommends that every organisation prioritise the catalogue.
Days from being added to being due, by the year CISA added the entry. At launch most older CVEs got six months and most 2021 CVEs two weeks. Three weeks was the norm from 2022 to 2025.
How defenders use it
- Patch these first. A listed flaw has already been used by attackers, whatever its CVSS score says. Of the entries here, 0 have known use in ransomware campaigns.
- Exposed systems before internal ones. Internet exposure is one of the factors that shortens a federal deadline to days, and internet-facing systems are the first thing attackers reach.
- Read it with the other signals. CVSS rates how severe a flaw would be, EPSS estimates the chance it is exploited in the next 30 days, and KEV records exploitation that has already happened. Frameworks such as SSVC weigh exploitation status, and CISA calls the catalogue the authoritative record of it.
- Automate the watch. Pull CISA's JSON feed every day, match new entries against your software inventory and alert on a hit. Many vulnerability scanners can flag catalogue entries for you.
- Look for intruders, not only holes. A patch closes the flaw; it does not remove anyone who used it first. For an exploited bug, check for signs of compromise too.
- Absence proves nothing. The catalogue lists only exploitation CISA has reliable evidence of, and "Unknown" ransomware use means unconfirmed, not ruled out.
Where this comes from
- CISA's Known Exploited Vulnerabilities catalogue, read from its JSON feed.
- CISA distributes the KEV database under CC0 1.0. This page is not affiliated with or endorsed by CISA or DHS.
- The snapshot keeps every entry's CVE ID, vendor, product, date added and ransomware and triage flags. The latest 80 are kept in full, with descriptions trimmed.
- Vendors appear as CISA names them.
- Every field was checked when the snapshot was built and again when this page loaded. Text from the catalogue reaches the page as plain text, and a CVE becomes a link to NVD only when it has the CVE-YYYY-NNNN form.
- Nothing is fetched: the page runs from the snapshot in this file. Links to NVD, MITRE's CWE list, FIRST and CISA open only when you follow them.