CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-27085 | HIGH | 8.8 | Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution. | Mar 11, 2021 |
| CVE-2021-27065 | HIGH | 7.8 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Mar 3, 2021 |
| CVE-2021-27059 | HIGH | 7.6 | Microsoft Office contains an unspecified vulnerability that allows for remote code execution. | Mar 11, 2021 |
| CVE-2021-26857 | HIGH | 7.8 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Mar 3, 2021 |
| CVE-2021-26855 | CRITICAL | 9.1 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Mar 3, 2021 |
| CVE-2021-26411 | HIGH | 8.8 | Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. | Mar 11, 2021 |
| CVE-2020-1054 | HIGH | 7.0 | Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. | May 21, 2020 |
| CVE-2023-23376 | HIGH | 7.8 | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Feb 14, 2023 |
| CVE-2023-21823 | HIGH | 7.8 | Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. | Feb 14, 2023 |
| CVE-2023-21715 | HIGH | 7.3 | Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. | Feb 14, 2023 |
| CVE-2023-21529 | HIGH | 8.8 | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Feb 14, 2023 |
| CVE-2022-26485 | HIGH | 8.8 | Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. | Dec 22, 2022 |
| CVE-2022-26486 | CRITICAL | 9.6 | Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. | Dec 22, 2022 |
| CVE-2025-62593 | HIGH | 8.8 | Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari. | Nov 26, 2025 |
| CVE-2026-33824 | UNKNOWN | — | Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. | Aug 18, 2026 |
| CVE-2026-9198 | CRITICAL | 9.8 | Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. | Jul 17, 2026 |
| CVE-2026-65400 | CRITICAL | 9.8 | Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. | Aug 6, 2026 |
| CVE-2026-68820 | HIGH | 7.0 | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Aug 11, 2026 |
| CVE-2022-21882 | HIGH | 7.0 | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Jan 11, 2022 |
| CVE-2021-4034 | HIGH | 7.8 | The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. | Jan 28, 2022 |
| CVE-2020-29574 | CRITICAL | 9.8 | CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. | Dec 11, 2020 |
| CVE-2020-0618 | HIGH | 8.8 | Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | Feb 11, 2020 |
| CVE-2019-5591 | MEDIUM | 6.5 | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. | Aug 14, 2020 |
| CVE-2026-32202 | MEDIUM | 4.3 | Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 |
| CVE-2026-59310 | CRITICAL | 9.8 | Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. | Jul 30, 2026 |