Tools / KEV calendar
When CISA says it has to be fixed.
Every entry in the Known Exploited Vulnerabilities catalogue comes with a date by which US federal agencies must have remediated it. That date is also the best public signal of how urgently CISA regards the exploitation, so here is the catalogue as a calendar: what is overdue, what is due this week, and what is coming, with the products each one affects.
43 overdue (last 30 days)8 due within 7 days8 due in the next 120 days0 used in ransomware
Subscribe as a calendar (.ics)Only for my products
Paste the .ics address into Outlook, Google Calendar or Apple Calendar as a subscribed calendar and the deadlines stay current.
Overdue
Past CISA's due date. For US federal agencies that is a missed mandate; for everyone else it is a vulnerability that has been exploited in the wild for weeks and is still unpatched.
21 August 2026
30 days ago · 4 CVEs
- CVE-2026-33824KEVCRITICAL 9.8EPSS 72.7%
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 18 August 2026
- CVE-2026-55040KEVCRITICAL 9.1EPSS 50.6%
Microsoft SharePoint Weak Authentication Vulnerability
microsoft/sharepoint server · added 18 August 2026
- CVE-2026-59310KEVCRITICAL 9.8EPSS 49.7%
Broadcom VMware vCenter Path Traversal Vulnerability
vmware/vcenter server · added 18 August 2026 · ransomware
- CVE-2026-65400KEVCRITICAL 9.8EPSS 10.5%
Apple macOS Improper Authentication Vulnerability
apple/macos · added 18 August 2026
23 August 2026
28 days ago · 1 CVE
- CVE-2026-72529KEVCRITICAL 9.3EPSS 1.55%
TrueConf Server Missing Authentication for Critical Function Vulnerability
trueconf/trueconf server · added 20 August 2026
24 August 2026
27 days ago · 1 CVE
- CVE-2026-73570KEVHIGH 8.9EPSS 32.4%
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
synacor/zimbra collaboration suite · added 21 August 2026
25 August 2026
26 days ago · 1 CVE
- CVE-2026-68820KEVHIGH 7.0EPSS 6.18%
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 11 August 2026
27 August 2026
24 days ago · 1 CVE
- CVE-2026-21962KEVCRITICAL 10.0EPSS 42.5%
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
oracle/http server · oracle/weblogic server proxy plug-in · added 24 August 2026
28 August 2026
23 days ago · 1 CVE
- CVE-2026-60004KEVCRITICAL 9.8EPSS 86.8%
Gitea Code Injection Vulnerability
gitea/gitea · added 25 August 2026
29 August 2026
22 days ago · 2 CVEs
- CVE-2019-1068KEVHIGH 8.8EPSS 52.8%
Microsoft SQL Server Remote Code Execution Vulnerability
microsoft/sql server · microsoft/sql server 2016 · microsoft/sql server 2017 · added 26 August 2026
- CVE-2026-8452KEVHIGH 8.8EPSS 1.61%
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
citrix/netscaler application delivery controller · citrix/netscaler gateway · added 26 August 2026
30 August 2026
21 days ago · 2 CVEs
- CVE-2023-49105KEVCRITICAL 9.8EPSS 43.2%
ownCloud Improper Authentication Vulnerability
owncloud/owncloud server · added 27 August 2026
- CVE-2026-53362KEVHIGH 7.8EPSS 0.51%
Linux Kernel Unspecified Vulnerability
linux/linux kernel · added 27 August 2026
2 September 2026
18 days ago · 1 CVE
- CVE-2026-64849KEVCRITICAL 9.3EPSS 16.4%
MLflow Server-Side Request Forgery Vulnerability
lfprojects/mlflow · added 19 August 2026
3 September 2026
17 days ago · 1 CVE
- CVE-2026-72530KEVCRITICAL 9.5EPSS 1.83%
TrueConf Server Code Injection Vulnerability
trueconf/trueconf server · added 20 August 2026
5 September 2026
15 days ago · 5 CVEs
- CVE-2026-49869KEVCRITICAL 10.0EPSS 1.92%
Kestra OSS OS Command Injection Vulnerability
kestra/kestra · added 2 September 2026
- CVE-2026-82329KEVCRITICAL 9.8EPSS 7.67%
JFrog Artifactory Improper Authentication Vulnerability
jfrog/artifactory · added 2 September 2026
- CVE-2026-83548KEVCRITICAL 10.0EPSS 4.67%
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
sonicwall/sma8200v · sonicwall/sma6210 firmware · sonicwall/sma7210 firmware · added 2 September 2026
- CVE-2026-83549KEVHIGH 7.8EPSS 8.51%
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
sonicwall/sma8200v · sonicwall/sma6210 firmware · sonicwall/sma7210 firmware · added 2 September 2026
- CVE-2026-9586KEVCRITICAL 9.3EPSS 11.8%
Sangoma Switchvox SQL Injection Vulnerability
sangoma/switchvox · added 2 September 2026
9 September 2026
11 days ago · 4 CVEs
- CVE-2015-3246KEVEXPLOIT ×2 ✓MEDIUM 5.1EPSS 8.80%
Red Hat Libuser Race Condition Vulnerability
redhat/enterprise linux · opensuse/opensuse · libuser project/libuser · added 26 August 2026
- CVE-2015-5287KEVEXPLOIT ×3 ✓HIGH 7.8EPSS 4.96%
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
redhat/automatic bug reporting tool · oracle/linux · redhat/enterprise linux · added 26 August 2026
- CVE-2021-23758KEVCRITICAL 9.8EPSS 83.6%
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
ajaxpro.2 project/ajaxpro.2 · michaelschwarz/ajax.net professional · added 26 August 2026
- CVE-2022-0995KEVHIGH 7.8EPSS 9.44%
Linux Kernel Out-of-Bounds Write Vulnerability
linux/linux kernel · fedoraproject/fedora · netapp/h300e firmware · added 26 August 2026
10 September 2026
10 days ago · 1 CVE
- CVE-2026-66384KEVMEDIUM 5.3EPSS 0.58%
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
jfrog/artifactory · added 27 August 2026
11 September 2026
9 days ago · 2 CVEs
- CVE-2026-75650KEVCRITICAL 10.0EPSS 2.15%
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
adobe/commerce · adobe/commerce b2b · adobe/magento · added 8 September 2026
- CVE-2026-86218KEVCRITICAL 10.0EPSS 7.49%
N-able N-central Static Code Injection Vulnerability
n-able/n-central · added 8 September 2026
12 September 2026
8 days ago · 3 CVEs
- CVE-2025-25249KEVCRITICAL 9.8EPSS 2.40%
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
fortinet/fortios · fortinet/fortiswitchmanager · fortinet/fortisase · added 9 September 2026
- CVE-2026-19490KEVCRITICAL 9.3EPSS 5.60%
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
citrix/netscaler application delivery controller · citrix/netscaler gateway · added 9 September 2026
- CVE-2026-20079KEVCRITICAL 10.0EPSS 75.8%
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
cisco/secure firewall management center · added 9 September 2026
13 September 2026
7 days ago · 2 CVEs
- CVE-2026-67277KEVHIGH 8.8EPSS 0.87%
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
mikrotik/routeros · added 10 September 2026
- CVE-2026-86060KEVCRITICAL 9.2EPSS 1.06%
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
mikrotik/routeros · added 10 September 2026
14 September 2026
6 days ago · 4 CVEs
- CVE-2026-84869KEVCRITICAL 9.9EPSS 0.69%
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
connectwise/screenconnect · added 11 September 2026
- CVE-2026-85706KEVCRITICAL 10.0EPSS 14.6%
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
gitlab/gitlab · added 11 September 2026
- CVE-2026-81578KEVHIGH 8.8EPSS 3.29%
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
papercut/papercut mf · papercut/papercut ng · added 31 August 2026
- CVE-2026-82078KEVCRITICAL 9.4EPSS 3.57%
PaperCut NG/MF Unsafe Reflection Vulnerability
papercut/papercut mf · papercut/papercut ng · added 31 August 2026
16 September 2026
4 days ago · 2 CVEs
- CVE-2026-48710KEVMEDIUM 6.5EPSS 36.3%
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
encode/starlette · redhat/ai inference server · redhat/ansible automation platform · added 2 September 2026
- CVE-2026-59822KEVHIGH 8.8EPSS 0.87%
BerriAI LiteLLM Improper Authentication Vulnerability
litellm/litellm · added 2 September 2026
17 September 2026
3 days ago · 1 CVE
- CVE-2026-76461KEVCRITICAL 9.8EPSS 2.01%
Cisco Secure Email Gateway SQL Injection Vulnerability
cisco/asyncos · added 14 September 2026
18 September 2026
2 days ago · 1 CVE
- CVE-2026-85046KEVHIGH 8.8EPSS 1.46%
Google Chromium V8 Type Confusion Vulnerability
google/chrome · google/v8 · added 4 September 2026
19 September 2026
1 day ago · 3 CVEs
- CVE-2026-58704KEVHIGH 8.8EPSS 0.21%
Google Pixel Improper Authorization Vulnerability
google/android · added 16 September 2026
- CVE-2026-76460KEVCRITICAL 10.0EPSS 0.78%
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
cisco/identity services engine · cisco/identity services engine passive identity connector · added 16 September 2026
- CVE-2026-87886KEVHIGH 7.8EPSS 0.25%
Acronis Backup Incorrect Default Permissions Vulnerability
acronis/acronis backup · added 16 September 2026
Due within seven days
Inside the next change window. If any of these are in your estate they should already be scheduled.
21 September 2026
in 1 day · 3 CVEs
- CVE-2025-39682KEVHIGH 7.1EPSS 1.20%
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
linux/linux kernel · debian/debian linux · added 18 September 2026
- CVE-2025-39964KEVMEDIUM 5.5EPSS 0.79%
Linux Kernel Race Condition Vulnerability
linux/linux kernel · siemens/simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware · siemens/simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · added 18 September 2026
- CVE-2026-53266KEVHIGH 8.8EPSS 0.28%
Linux Kernel Out-of-Bounds Write Vulnerability
linux/linux kernel · added 18 September 2026
22 September 2026
in 2 days · 2 CVEs
- CVE-2026-81963KEVHIGH 7.8EPSS 0.63%
Microsoft Windows Link Following Vulnerability
microsoft/windows 11 23h2 · microsoft/windows 11 24h2 · microsoft/windows 11 25h2 · added 8 September 2026
- CVE-2026-85880KEVHIGH 7.8EPSS 0.57%
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 8 September 2026
23 September 2026
in 3 days · 1 CVE
- CVE-2026-87491KEVHIGH 8.8EPSS 1.00%
Google Chromium V8 Out of Bounds Write Vulnerability
google/chrome · added 9 September 2026
25 September 2026
in 5 days · 2 CVEs
- CVE-2026-42016KEVHIGH 8.8EPSS 9.06%
JFrog Artifactory Incorrect Authorization Vulnerability
jfrog/artifactory · added 11 September 2026
- CVE-2026-42018KEVHIGH 7.5EPSS 11.0%
JFrog Artifactory Improper Authentication Vulnerability
jfrog/artifactory · added 11 September 2026
How to use the dates
Binding Operational Directive 22-01 obliges US federal civilian agencies to remediate each KEV entry by its due date. Nothing obliges a UK organisation, but the catalogue is the shortest list of vulnerabilities that are definitely being exploited, and the due dates are a ready-made prioritisation: CISA sets them shorter when the exploitation is broad or the impact severe. Treat an entry in your estate as an emergency change regardless of the date, and treat an overdue one as a reason to hunt for prior compromise as well as to patch.
The CVE watchlist narrows this to your own products and includes KEV additions in its feed and email; each CVE Explorer page shows the deadline alongside the CVSS and EPSS scores. Data from CISA, refreshed every four hours.