SOC status:Duty analyst on shift

UK Cyber Defence

Tools / KEV calendar

When CISA says it has to be fixed.

Every entry in the Known Exploited Vulnerabilities catalogue comes with a date by which US federal agencies must have remediated it. That date is also the best public signal of how urgently CISA regards the exploitation, so here is the catalogue as a calendar: what is overdue, what is due this week, and what is coming, with the products each one affects.

43 overdue (last 30 days)8 due within 7 days8 due in the next 120 days0 used in ransomware

Subscribe as a calendar (.ics)Only for my products

Paste the .ics address into Outlook, Google Calendar or Apple Calendar as a subscribed calendar and the deadlines stay current.

Overdue

Past CISA's due date. For US federal agencies that is a missed mandate; for everyone else it is a vulnerability that has been exploited in the wild for weeks and is still unpatched.

21 August 2026

30 days ago · 4 CVEs

  • CVE-2026-33824

    Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 18 August 2026

    KEVCRITICAL 9.8EPSS 72.7%
  • CVE-2026-55040

    Microsoft SharePoint Weak Authentication Vulnerability

    microsoft/sharepoint server · added 18 August 2026

    KEVCRITICAL 9.1EPSS 50.6%
  • CVE-2026-59310

    Broadcom VMware vCenter Path Traversal Vulnerability

    vmware/vcenter server · added 18 August 2026 · ransomware

    KEVCRITICAL 9.8EPSS 49.7%
  • CVE-2026-65400

    Apple macOS Improper Authentication Vulnerability

    apple/macos · added 18 August 2026

    KEVCRITICAL 9.8EPSS 10.5%

23 August 2026

28 days ago · 1 CVE

  • CVE-2026-72529

    TrueConf Server Missing Authentication for Critical Function Vulnerability

    trueconf/trueconf server · added 20 August 2026

    KEVCRITICAL 9.3EPSS 1.55%

24 August 2026

27 days ago · 1 CVE

  • CVE-2026-73570

    Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    synacor/zimbra collaboration suite · added 21 August 2026

    KEVHIGH 8.9EPSS 32.4%

25 August 2026

26 days ago · 1 CVE

  • CVE-2026-68820

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 11 August 2026

    KEVHIGH 7.0EPSS 6.18%

27 August 2026

24 days ago · 1 CVE

  • CVE-2026-21962

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    oracle/http server · oracle/weblogic server proxy plug-in · added 24 August 2026

    KEVCRITICAL 10.0EPSS 42.5%

28 August 2026

23 days ago · 1 CVE

  • CVE-2026-60004

    Gitea Code Injection Vulnerability

    gitea/gitea · added 25 August 2026

    KEVCRITICAL 9.8EPSS 86.8%

29 August 2026

22 days ago · 2 CVEs

  • CVE-2019-1068

    Microsoft SQL Server Remote Code Execution Vulnerability

    microsoft/sql server · microsoft/sql server 2016 · microsoft/sql server 2017 · added 26 August 2026

    KEVHIGH 8.8EPSS 52.8%
  • CVE-2026-8452

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    citrix/netscaler application delivery controller · citrix/netscaler gateway · added 26 August 2026

    KEVHIGH 8.8EPSS 1.61%

30 August 2026

21 days ago · 2 CVEs

  • CVE-2023-49105

    ownCloud Improper Authentication Vulnerability

    owncloud/owncloud server · added 27 August 2026

    KEVCRITICAL 9.8EPSS 43.2%
  • CVE-2026-53362

    Linux Kernel Unspecified Vulnerability

    linux/linux kernel · added 27 August 2026

    KEVHIGH 7.8EPSS 0.51%

2 September 2026

18 days ago · 1 CVE

  • CVE-2026-64849

    MLflow Server-Side Request Forgery Vulnerability

    lfprojects/mlflow · added 19 August 2026

    KEVCRITICAL 9.3EPSS 16.4%

3 September 2026

17 days ago · 1 CVE

  • CVE-2026-72530

    TrueConf Server Code Injection Vulnerability

    trueconf/trueconf server · added 20 August 2026

    KEVCRITICAL 9.5EPSS 1.83%

5 September 2026

15 days ago · 5 CVEs

  • CVE-2026-49869

    Kestra OSS OS Command Injection Vulnerability

    kestra/kestra · added 2 September 2026

    KEVCRITICAL 10.0EPSS 1.92%
  • CVE-2026-82329

    JFrog Artifactory Improper Authentication Vulnerability

    jfrog/artifactory · added 2 September 2026

    KEVCRITICAL 9.8EPSS 7.67%
  • CVE-2026-83548

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    sonicwall/sma8200v · sonicwall/sma6210 firmware · sonicwall/sma7210 firmware · added 2 September 2026

    KEVCRITICAL 10.0EPSS 4.67%
  • CVE-2026-83549

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    sonicwall/sma8200v · sonicwall/sma6210 firmware · sonicwall/sma7210 firmware · added 2 September 2026

    KEVHIGH 7.8EPSS 8.51%
  • CVE-2026-9586

    Sangoma Switchvox SQL Injection Vulnerability

    sangoma/switchvox · added 2 September 2026

    KEVCRITICAL 9.3EPSS 11.8%

9 September 2026

11 days ago · 4 CVEs

  • CVE-2015-3246

    Red Hat Libuser Race Condition Vulnerability

    redhat/enterprise linux · opensuse/opensuse · libuser project/libuser · added 26 August 2026

    KEVEXPLOIT ×2MEDIUM 5.1EPSS 8.80%
  • CVE-2015-5287

    Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

    redhat/automatic bug reporting tool · oracle/linux · redhat/enterprise linux · added 26 August 2026

    KEVEXPLOIT ×3HIGH 7.8EPSS 4.96%
  • CVE-2021-23758

    Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

    ajaxpro.2 project/ajaxpro.2 · michaelschwarz/ajax.net professional · added 26 August 2026

    KEVCRITICAL 9.8EPSS 83.6%
  • CVE-2022-0995

    Linux Kernel Out-of-Bounds Write Vulnerability

    linux/linux kernel · fedoraproject/fedora · netapp/h300e firmware · added 26 August 2026

    KEVHIGH 7.8EPSS 9.44%

10 September 2026

10 days ago · 1 CVE

  • CVE-2026-66384

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    jfrog/artifactory · added 27 August 2026

    KEVMEDIUM 5.3EPSS 0.58%

11 September 2026

9 days ago · 2 CVEs

  • CVE-2026-75650

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    adobe/commerce · adobe/commerce b2b · adobe/magento · added 8 September 2026

    KEVCRITICAL 10.0EPSS 2.15%
  • CVE-2026-86218

    N-able N-central Static Code Injection Vulnerability

    n-able/n-central · added 8 September 2026

    KEVCRITICAL 10.0EPSS 7.49%

12 September 2026

8 days ago · 3 CVEs

  • CVE-2025-25249

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    fortinet/fortios · fortinet/fortiswitchmanager · fortinet/fortisase · added 9 September 2026

    KEVCRITICAL 9.8EPSS 2.40%
  • CVE-2026-19490

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    citrix/netscaler application delivery controller · citrix/netscaler gateway · added 9 September 2026

    KEVCRITICAL 9.3EPSS 5.60%
  • CVE-2026-20079

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    cisco/secure firewall management center · added 9 September 2026

    KEVCRITICAL 10.0EPSS 75.8%

13 September 2026

7 days ago · 2 CVEs

  • CVE-2026-67277

    MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

    mikrotik/routeros · added 10 September 2026

    KEVHIGH 8.8EPSS 0.87%
  • CVE-2026-86060

    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    mikrotik/routeros · added 10 September 2026

    KEVCRITICAL 9.2EPSS 1.06%

14 September 2026

6 days ago · 4 CVEs

  • CVE-2026-84869

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    connectwise/screenconnect · added 11 September 2026

    KEVCRITICAL 9.9EPSS 0.69%
  • CVE-2026-85706

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    gitlab/gitlab · added 11 September 2026

    KEVCRITICAL 10.0EPSS 14.6%
  • CVE-2026-81578

    PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

    papercut/papercut mf · papercut/papercut ng · added 31 August 2026

    KEVHIGH 8.8EPSS 3.29%
  • CVE-2026-82078

    PaperCut NG/MF Unsafe Reflection Vulnerability

    papercut/papercut mf · papercut/papercut ng · added 31 August 2026

    KEVCRITICAL 9.4EPSS 3.57%

16 September 2026

4 days ago · 2 CVEs

  • CVE-2026-48710

    Kludex Starlette HTTP Request/Response Smuggling Vulnerability

    encode/starlette · redhat/ai inference server · redhat/ansible automation platform · added 2 September 2026

    KEVMEDIUM 6.5EPSS 36.3%
  • CVE-2026-59822

    BerriAI LiteLLM Improper Authentication Vulnerability

    litellm/litellm · added 2 September 2026

    KEVHIGH 8.8EPSS 0.87%

17 September 2026

3 days ago · 1 CVE

  • CVE-2026-76461

    Cisco Secure Email Gateway SQL Injection Vulnerability

    cisco/asyncos · added 14 September 2026

    KEVCRITICAL 9.8EPSS 2.01%

18 September 2026

2 days ago · 1 CVE

  • CVE-2026-85046

    Google Chromium V8 Type Confusion Vulnerability

    google/chrome · google/v8 · added 4 September 2026

    KEVHIGH 8.8EPSS 1.46%

19 September 2026

1 day ago · 3 CVEs

  • CVE-2026-58704

    Google Pixel Improper Authorization Vulnerability

    google/android · added 16 September 2026

    KEVHIGH 8.8EPSS 0.21%
  • CVE-2026-76460

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    cisco/identity services engine · cisco/identity services engine passive identity connector · added 16 September 2026

    KEVCRITICAL 10.0EPSS 0.78%
  • CVE-2026-87886

    Acronis Backup Incorrect Default Permissions Vulnerability

    acronis/acronis backup · added 16 September 2026

    KEVHIGH 7.8EPSS 0.25%

Due within seven days

Inside the next change window. If any of these are in your estate they should already be scheduled.

21 September 2026

in 1 day · 3 CVEs

  • CVE-2025-39682

    Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    linux/linux kernel · debian/debian linux · added 18 September 2026

    KEVHIGH 7.1EPSS 1.20%
  • CVE-2025-39964

    Linux Kernel Race Condition Vulnerability

    linux/linux kernel · siemens/simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware · siemens/simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · added 18 September 2026

    KEVMEDIUM 5.5EPSS 0.79%
  • CVE-2026-53266

    Linux Kernel Out-of-Bounds Write Vulnerability

    linux/linux kernel · added 18 September 2026

    KEVHIGH 8.8EPSS 0.28%

22 September 2026

in 2 days · 2 CVEs

  • CVE-2026-81963

    Microsoft Windows Link Following Vulnerability

    microsoft/windows 11 23h2 · microsoft/windows 11 24h2 · microsoft/windows 11 25h2 · added 8 September 2026

    KEVHIGH 7.8EPSS 0.63%
  • CVE-2026-85880

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · added 8 September 2026

    KEVHIGH 7.8EPSS 0.57%

23 September 2026

in 3 days · 1 CVE

  • CVE-2026-87491

    Google Chromium V8 Out of Bounds Write Vulnerability

    google/chrome · added 9 September 2026

    KEVHIGH 8.8EPSS 1.00%

25 September 2026

in 5 days · 2 CVEs

  • CVE-2026-42016

    JFrog Artifactory Incorrect Authorization Vulnerability

    jfrog/artifactory · added 11 September 2026

    KEVHIGH 8.8EPSS 9.06%
  • CVE-2026-42018

    JFrog Artifactory Improper Authentication Vulnerability

    jfrog/artifactory · added 11 September 2026

    KEVHIGH 7.5EPSS 11.0%

How to use the dates

Binding Operational Directive 22-01 obliges US federal civilian agencies to remediate each KEV entry by its due date. Nothing obliges a UK organisation, but the catalogue is the shortest list of vulnerabilities that are definitely being exploited, and the due dates are a ready-made prioritisation: CISA sets them shorter when the exploitation is broad or the impact severe. Treat an entry in your estate as an emergency change regardless of the date, and treat an overdue one as a reason to hunt for prior compromise as well as to patch.

The CVE watchlist narrows this to your own products and includes KEV additions in its feed and email; each CVE Explorer page shows the deadline alongside the CVSS and EPSS scores. Data from CISA, refreshed every four hours.