CISA KEV & Exploit Status
The CISA Known Exploited Vulnerabilities catalog tracks CVEs with confirmed active exploitation. Coverage includes new KEV additions, BOD 22-01 remediation deadlines, EPSS context, and guidance on using KEV status for patch prioritization.

SharePoint Code Injection CVE-2026-65660 Added to KEV
CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

Zyxel, Veeam Flaws Confirmed Under Active Exploitation
CISA added Zyxel GS1900 CVE-2026-7273 to its KEV catalog September 21. Veeam Agent CVE-2026-32996 also actively exploited. Patches available for both.

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

CISA Adds N-able N-central Auth Bypass to KEV
CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

CISA Adds Seven Exploited Flaws to KEV Catalog
CISA added seven actively exploited vulnerabilities to KEV on September 3, including a critical Sangoma Switchvox SQL injection. Federal agencies face BOD 26-04 remediation deadlines.

What Is EPSS? Exploit Prediction Scoring Explained
EPSS scores predict 30-day exploitation probability. A CVE with CVSS 6.5 and EPSS 0.94 deserves more urgency than a CVSS 9.8 with EPSS 0.01.

What Is the CISA KEV Catalog?
CISA's Known Exploited Vulnerabilities catalog explained: what gets added, why it matters beyond federal agencies, and how to use it to prioritize patching.