
Known Exploited Vulnerabilities
CISA's catalogue of CVEs confirmed as actively exploited; mandatory patch deadlines for US federal agencies.
CISA added 39 flaws to the KEV catalogue between 10 June and 29 July 2026; 34 carried a three-day-or-less remediation window, up from 12 of 31 in the prior seven weeks, while the catalogue's own growth held steady near 0.78 entries a day either side of the change.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Is the 2022 patch or the 2024 patch the one breaking into networks right now?
Timeline for Known Exploited Vulnerabilities
Recorded a shortened remediation-deadline distribution since 10 June
Cybersecurity: Threats and Defences: KEV patch clocks fell to three daysMentioned in: SharePoint stays under active KEV fire
Cybersecurity: Threats and DefencesMentioned in: Langflow hits KEV a second time
Cybersecurity: Threats and DefencesMentioned in: CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesMentioned in: Oracle EBS gets a 3-day patch clock
Cybersecurity: Threats and DefencesBackground
The CISA Known Exploited Vulnerabilities catalogue is the primary operational mechanism for communicating mandatory patch obligations to Federal Civilian Executive Branch agencies and urgency signals to private-sector organisations. Established under Binding Operational Directive 22-01 in November 2021, it originally set fixed windows, typically 14 days for non-critical flaws and 2-7 days for critical ones. Private-sector organisations are not bound by the directive but treat KEV addition as the strongest available public signal of active exploitation, and it drives patch-prioritisation tooling across most major vulnerability management platforms.
That fixed-window regime was formally revoked on 10 June 2026 when CISA issued Binding Operational Directive 26-04, replacing it with a four-tier model, 3 days, 14 days, 60 days, or next upgrade cycle, calibrated against exploitability, exposure, asset criticality and observed threat-actor behaviour rather than a binary critical/non-critical split.
CISA's KEV deadlines tightened sharply
CISA added 39 flaws to the Known Exploited Vulnerabilities catalogue between 10 June and 29 July 2026, the window since Binding Operational Directive 26-04 replaced fixed patch windows with a four-tier, risk-based model. Thirty-four of those 39 entries, 87 per cent, carried a remediation window of three days or less, against 12 of 31 entries in the prior seven weeks, 39 per cent; the median time allowed fell from 14 days to three.
What did not change was the underlying pace: additions held near 0.78 entries a day both before and after the directive, putting the catalogue at 1,656 entries by version 2026.07.29. CISA's own published counts sit awkwardly against a widely repeated 'two a day' estimate: roughly 1,627 entries in mid-June against 1,656 by late July works out closer to 0.64 a day over that stretch, evidence the catalogue's growth rate is easy to overstate if quoted loosely rather than measured against the agency's own version-dated figures.
It sets deadlines before fixes exist
A pattern emerged across three KEV additions in twelve days in May 2026: CISA imposed federal compliance deadlines before vendor patches were even available. PAN-OS CVE-2026-0300 was added on 6 May with a 9 May Deadline, four days before Palo Alto's own patch shipped.
Cisco SD-WAN CVE-2026-20182 (CVSS 10.0) followed on 14 May with a 17 May Deadline, and Exchange Server CVE-2026-42897 was added on 15 May with a 29 May Deadline while Microsoft had not yet shipped a fix. The repeat within twelve days reframes the first instance from a one-off forced by exploitation Velocity into a deliberate posture: CISA is willing to set a federal Deadline against a flaw with no available fix.