CVEDigest

Known Exploited Vulnerabilities (KEV) timeline

The CISA Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities with reliable evidence of active exploitation in the wild. It is the single best patch-prioritization shortlist: if a flaw is on it, attackers are already using it. This timeline tracks 40 high-impact entries — 0 rated Critical and 8 with known ransomware-campaign use — newest first, each linking to a plain-English explainer and remediation steps. CISA remediation due dates are binding on U.S. federal civilian agencies; everyone else should treat them as strong urgency signals.

Source: CISA Known Exploited Vulnerabilities Catalog. Data as of 2026-06-13.

At a glance

Timeline (newest first)

Added in 2026

Frequently asked questions

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) of vulnerabilities with reliable evidence of active exploitation in the wild. It was established under Binding Operational Directive 22-01 and is widely used as a patch-prioritization shortlist.

How is a vulnerability added to the KEV catalog?

A CVE is added when it has an assigned CVE ID, there is reliable evidence it is being exploited in the wild, and there is a clear remediation action such as a vendor patch. It is not a list of every severe vulnerability — only those known to be exploited.

Does the KEV due date apply to my company?

The remediation due dates are legally binding only on U.S. federal civilian executive-branch agencies under BOD 22-01. However, CISA and most security teams recommend that private and other organizations use the same dates as a strong prioritization signal.

What does 'Known ransomware campaign use' mean?

It flags KEV entries that CISA has linked to ransomware operations. These deserve elevated urgency because exploitation has been observed as part of attacks that encrypt or steal data for extortion.

Browse another way

Prefer a sortable table? See the full CVE catalog. For how this list is sourced and refreshed, read our methodology.

Last updated: 2026-06-13