Nucleus Security CISA KEV Enrichment Dashboard provides insights into vulnerability prioritizationHelp Net Security·Nov 3, 00:00 UTC · Nov 3, 2022Exploit / PoC in the wild60
CISA Urged to Enrich KEV Catalog with More Contextual DataInfosecurity Magazine·May 30, 09:00 UTC · May 30, 2025Exploit / PoC in the wild60
CISA: Agencies seeing steep decrease in known exploited vulnerabilities on federal networksThe Record·Oct 26, 19:22 UTC · Oct 26, 2023Exploit / PoC in the wild60
Third of Exploited Flaws Weaponized Within a Day of DisclosureInfosecurity Magazine·Jul 30, 12:45 UTC · Jul 30, 2025Exploit / PoC in the wild60
Millions still exposed despite available fixesHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2023Exploit / PoC in the wild60
Just 1% of AI-Discovered Vulnerabilities Exploited in the WildInfosecurity Magazine·Jul 29, 10:15 UTC · Jul 29, 2026Exploit / PoC in the wild60
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target EnterprisesThe Hacker News·Jul 18, 04:54 UTC · Jul 18, 2025Exploit / PoC in the wildCVE-2025-5777CVE-2023-4966CVE-2025-6543+1 CVEs60
CISA Adds Three Security Flaws with Active Exploitation to KEV CatalogThe Hacker News·Nov 18, 04:36 UTC · Nov 18, 2023Exploit / PoC in the wildCVE-2023-36584CVE-2023-1671CVE-2020-2551+4 CVEs60
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEVThe Hacker News·Apr 29, 08:46 UTC · Apr 29, 2026Exploit / PoC in the wildCVE-2024-1708CVE-2026-32202CVE-2026-21510+2 CVEs160
CISA Adds CVE-2025-53521 to KEV After Active F5 BIGThe Hacker News·Mar 28, 08:37 UTC · Mar 28, 2026Exploit / PoC in the wildCVE-2025-5352160
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV CatalogThe Hacker News·Mar 6, 06:30 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2017-7921CVE-2021-2268160
CISA Shifts Alert Distribution Strategy to Email, Social MediaInfosecurity Magazine·May 13, 15:15 UTC · May 13, 2025Exploit / PoC in the wild60
CISA Adds Second BeyondTrust Flaw to KEV Catalog Amid Active AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Exploit / PoC in the wildCVE-2024-12686CVE-2024-12356CVE-2023-4836560
CISA's KEV Catalog Updated with 3 New Flaws Threatening IT Management SystemsThe Hacker News·Mar 11, 06:26 UTC · Mar 11, 2023Exploit / PoC in the wildCVE-2022-35914CVE-2022-33891CVE-2022-28810+3 CVEs60
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe Hacker News·Jul 25, 09:59 UTC · Jul 25, 2026Exploit / PoC in the wildCVE-2026-1256960
CISA's new KEV nomination form opens reporting to vendors and researchersHelp Net Security·Jun 19, 12:14 UTC · Jun 19, 2026Exploit / PoC in the wild60
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026The Hacker News·Mar 21, 08:25 UTC · Mar 21, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+2 CVEs160
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation EvidenceThe Hacker News·Nov 5, 06:12 UTC · Nov 5, 2025Exploit / PoC in the wildCVE-2025-11371CVE-2025-48703CVE-2025-11533+2 CVEs60
CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Sep 3, 07:38 UTC · Sep 3, 2025Exploit / PoC in the wildCVE-2020-24363CVE-2025-55177CVE-2025-4330060
Is Ivanti the problem or a symptom of a systemic issue with network devices?CyberScoop·Apr 14, 13:57 UTC · Apr 14, 2025Exploit / PoC in the wild60
CISA Adds NAKIVO Vulnerability to KEV Catalog Amid Active ExploitationThe Hacker News·Mar 26, 08:35 UTC · Mar 26, 2025Exploit / PoC in the wildCVE-2024-48248CVE-2025-1316CVE-2017-1263760
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Feb 26, 04:33 UTC · Feb 26, 2025Exploit / PoC in the wildCVE-2024-49035CVE-2023-3419260
CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut BugThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2023Exploit / PoC in the wildCVE-2023-28432CVE-2023-27350CVE-2023-213660
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsThe Hacker News·Aug 8, 06:52 UTC · Aug 8, 2026Exploit / PoC in the wildCVE-2026-803760
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe Hacker News·Jul 9, 10:22 UTC · Jul 9, 2026Exploit / PoC in the wildCVE-2026-48282CVE-2026-56290CVE-2026-55255+7 CVEs60
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Jun 10, 14:44 UTC · Jun 10, 2026Exploit / PoC in the wildCVE-2026-20245CVE-2026-11645CVE-2026-747360
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active ExploitationThe Hacker News·Jun 2, 18:14 UTC · Jun 2, 2026Exploit / PoC in the wildCVE-2024-21182CVE-2026-2196260
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEVThe Hacker News·May 23, 13:25 UTC · May 23, 2026Exploit / PoC in the wildCVE-2026-908260
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active ExploitationThe Hacker News·Apr 17, 13:10 UTC · Apr 17, 2026Exploit / PoC in the wildCVE-2026-34197CVE-2024-32114CVE-2023-4660460
CISA Adds Two Actively Exploited Roundcube Flaws to KEV CatalogThe Hacker News·Feb 21, 07:21 UTC · Feb 21, 2026Exploit / PoC in the wildCVE-2025-49113CVE-2025-6846160
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
Zero-Day Exploits Surge, 30% of Flaws Attacked Before DisclosureInfosecurity Magazine·Jan 22, 12:45 UTC · Jan 22, 2026Exploit / PoC in the wild60
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV CatalogThe Hacker News·Dec 12, 05:04 UTC · Dec 12, 2025Exploit / PoC in the wildCVE-2025-58360CVE-2024-3640160
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
Trick, treat, repeatCisco Talos·Oct 30, 18:00 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-5928760
Actively Exploited WSUS Bug Added to CISA KEV ListInfosecurity Magazine·Oct 28, 09:45 UTC · Oct 28, 2025Exploit / PoC in the wildCVE-2025-5928760
CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation EvidenceThe Hacker News·Aug 6, 06:51 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2020-25078CVE-2020-25079CVE-2020-4079960
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation ConfirmedThe Hacker News·May 10, 06:43 UTC · May 10, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2025-392860