Update Tracker · Vulnerability data

CISA Known Exploited Vulnerabilities Tracker

Every CVE the US government has confirmed is being exploited in the wild — not theoretically exploitable, actively used against real targets. Search by CVE, vendor or product.

Feed healthy · verified 30 Jul 2026 1,656 entries 66 past due, added in the last 90 days
Source CISA KEV feed
Last verified 30 Jul 2026
Next check 01 Aug 2026
CadenceEvery 12 hours
Confidence confirmed
19 of 1,656 shown

Added in the last 7 days 3

Edge & VPN appliances 8

Ransomware-linked 8

JSON API Download CSV Primary source Showing 19 representative entries of 1,656

How this tracker is built

Twice a day a scheduled job fetches the official CISA JSON feed, normalises the field names, and compares every record against the copy we already hold. Anything that differs is written to the change log in the sidebar. Nothing on this page is edited by hand.

If a fetch fails, we keep the previous data and its original verified date. You will see the timestamp go stale rather than see fresh-looking data that is actually old. After three consecutive failures the page carries a warning banner and we get an email.

What the labels mean

  • Ransomware — CISA has confirmed the vulnerability was used in a ransomware campaign. That is their field, not our judgement.
  • Critical / High / Medium — the NVD CVSS v3.1 base score. KEV entries carry no severity of their own.
  • Patched — a fix is available and we have seen no exploitation reported in 90 days. The entry stays in the catalog regardless.

Why the due dates matter to you

The due date is the deadline by which US federal civilian agencies must remediate, under Binding Operational Directive 22-01. It is not a deadline for anyone else.

It is still the most useful urgency signal available, because CISA sets it based on how actively the flaw is being used rather than on CVSS. A two-week due date means something is on fire right now.

Known limitations

KEV is not a complete list of exploited vulnerabilities. It is the list CISA has confirmed and chosen to publish. Absence from this catalog is not evidence that something is safe.

Vendors also occasionally revise affected version ranges after publication. Where that happens, the revision appears in the change log rather than silently replacing what was there before.

Share this tracker

Was this tracker helpful?

If something here is wrong or out of date, tell us and we will check the source.

Last verified July 30, 2026 · maintained by Arjun Nair