Live mirror of the federal catalog of vulnerabilities actively exploited in the wild. When a federal RFP names tech with an open KEV entry, the procurement is implicitly urgent: agencies are racing against active exploitation.
21% of total
across 685 products
| CVE | Vendor / Product | Vulnerability | Added | RW |
|---|---|---|---|---|
| CVE-2026-85046 | Google Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 2026-09-04 | - |
| CVE-2026-9586 | Sangoma Switchvox | Sangoma Switchvox SQL Injection Vulnerability | 2026-09-02 | - |
| CVE-2026-83549 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | 2026-09-02 | - |
| CVE-2026-83548 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 2026-09-02 | - |
| CVE-2026-82329 | JFrog Artifactory | JFrog Artifactory Improper Authentication Vulnerability | 2026-09-02 | - |
| CVE-2026-59822 | BerriAI LiteLLM | BerriAI LiteLLM Improper Authentication Vulnerability | 2026-09-02 | - |
| CVE-2026-49869 | Kestra Kestra OSS | Kestra OSS OS Command Injection Vulnerability | 2026-09-02 | - |
| CVE-2026-48710 | Kludex Starlette | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 2026-09-02 | - |
| CVE-2026-82078 | PaperCut NG/MF | PaperCut NG/MF Unsafe Reflection Vulnerability | 2026-08-31 | - |
| CVE-2026-81578 | PaperCut NG/MF | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | 2026-08-31 | - |
| CVE-2026-66384 | JFrog Artifactory | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 2026-08-27 | - |
| CVE-2026-53362 | Linux Kernel | Linux Kernel Unspecified Vulnerability | 2026-08-27 | - |
| CVE-2023-49105 | ownCloud ownCloud | ownCloud Improper Authentication Vulnerability | 2026-08-27 | - |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 2026-08-26 | - |
| CVE-2022-0995 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 2026-08-26 | - |
| CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 2026-08-26 | - |
| CVE-2019-1068 | Microsoft SQL Server | Microsoft SQL Server Remote Code Execution Vulnerability | 2026-08-26 | - |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 2026-08-26 | - |
| CVE-2015-3246 | Red Hat Libuser | Red Hat Libuser Race Condition Vulnerability | 2026-08-26 | - |
| CVE-2026-60004 | Gitea Gitea | Gitea Code Injection Vulnerability | 2026-08-25 | - |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 2026-08-24 | - |
| CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 2026-08-21 | - |
| CVE-2026-72530 | TrueConf Server | TrueConf Server Code Injection Vulnerability | 2026-08-20 | - |
| CVE-2026-72529 | TrueConf Server | TrueConf Server Missing Authentication for Critical Function Vulnerability | 2026-08-20 | - |
| CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery Vulnerability | 2026-08-19 | - |
| CVE-2026-65400 | Apple macOS | Apple macOS Improper Authentication Vulnerability | 2026-08-18 | - |
| CVE-2026-59310 | Broadcom VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability | 2026-08-18 | - |
| CVE-2026-55040 | Microsoft SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | 2026-08-18 | - |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 2026-08-18 | - |
| CVE-2025-62593 | Ray-Project Ray | Ray-Project Ray Code Injection Vulnerability | 2026-08-17 | - |
| CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection Vulnerability | 2026-08-11 | - |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2026-08-11 | - |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 2026-08-11 | - |
| CVE-2026-8037 | Progress LoadMaster | Progress LoadMaster Command Injection Vulnerability | 2026-08-07 | - |
| CVE-2026-63077 | JetBrains TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 2026-08-05 | - |
| CVE-2026-9198 | IBM Langflow | IBM Langflow Code Injection Vulnerability | 2026-08-04 | - |
| CVE-2026-34486 | Apache Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 2026-08-04 | - |
| CVE-2026-18556 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-04 | - |
| CVE-2026-18577 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-08-03 | - |
| CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 2026-07-29 | - |
| CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 2026-07-27 | - |
| CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-07-27 | - |
| CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-22 | - |
| CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 2026-07-22 | - |
| CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | 2026-07-21 | - |
| CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | 2026-07-21 | - |
| CVE-2026-0770 | Langflow Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 2026-07-21 | - |
| CVE-2021-27137 | DD-WRT DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | 2026-07-21 | - |
| CVE-2026-58644 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-16 | - |
| CVE-2026-39808 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 2026-07-16 | - |
Source: CISA Known Exploited Vulnerabilities Catalog via cisagov/kev-data. Refreshed daily. Catalog version as of 2026-09-04.