Skip to content
You can now search across every topic, entity and event.What's new
Known Exploited Vulnerabilities
ConceptUS

Known Exploited Vulnerabilities

CISA's catalogue of CVEs confirmed as actively exploited; mandatory patch deadlines for US federal agencies.

CISA added 39 flaws to the KEV catalogue between 10 June and 29 July 2026; 34 carried a three-day-or-less remediation window, up from 12 of 31 in the prior seven weeks, while the catalogue's own growth held steady near 0.78 entries a day either side of the change.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Is the 2022 patch or the 2024 patch the one breaking into networks right now?

Timeline for Known Exploited Vulnerabilities

#12 28 Jul

Recorded a shortened remediation-deadline distribution since 10 June

Cybersecurity: Threats and Defences: KEV patch clocks fell to three days
#11 22 Jul

Mentioned in: SharePoint stays under active KEV fire

Cybersecurity: Threats and Defences
#11 21 Jul

Mentioned in: Langflow hits KEV a second time

Cybersecurity: Threats and Defences
#11 16 Jul

Mentioned in: CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#11 15 Jul

Mentioned in: Oracle EBS gets a 3-day patch clock

Cybersecurity: Threats and Defences
View full timeline →

Background

The CISA Known Exploited Vulnerabilities catalogue is the primary operational mechanism for communicating mandatory patch obligations to Federal Civilian Executive Branch agencies and urgency signals to private-sector organisations. Established under Binding Operational Directive 22-01 in November 2021, it originally set fixed windows, typically 14 days for non-critical flaws and 2-7 days for critical ones. Private-sector organisations are not bound by the directive but treat KEV addition as the strongest available public signal of active exploitation, and it drives patch-prioritisation tooling across most major vulnerability management platforms.

That fixed-window regime was formally revoked on 10 June 2026 when CISA issued Binding Operational Directive 26-04, replacing it with a four-tier model, 3 days, 14 days, 60 days, or next upgrade cycle, calibrated against exploitability, exposure, asset criticality and observed threat-actor behaviour rather than a binary critical/non-critical split.

Key Issues
Deadline severity

CISA's KEV deadlines tightened sharply

CISA added 39 flaws to the Known Exploited Vulnerabilities catalogue between 10 June and 29 July 2026, the window since Binding Operational Directive 26-04 replaced fixed patch windows with a four-tier, risk-based model. Thirty-four of those 39 entries, 87 per cent, carried a remediation window of three days or less, against 12 of 31 entries in the prior seven weeks, 39 per cent; the median time allowed fell from 14 days to three.

What did not change was the underlying pace: additions held near 0.78 entries a day both before and after the directive, putting the catalogue at 1,656 entries by version 2026.07.29. CISA's own published counts sit awkwardly against a widely repeated 'two a day' estimate: roughly 1,627 entries in mid-June against 1,656 by late July works out closer to 0.64 a day over that stretch, evidence the catalogue's growth rate is easy to overstate if quoted loosely rather than measured against the agency's own version-dated figures.

Deadlines before patches

It sets deadlines before fixes exist

A pattern emerged across three KEV additions in twelve days in May 2026: CISA imposed federal compliance deadlines before vendor patches were even available. PAN-OS CVE-2026-0300 was added on 6 May with a 9 May Deadline, four days before Palo Alto's own patch shipped.

Cisco SD-WAN CVE-2026-20182 (CVSS 10.0) followed on 14 May with a 17 May Deadline, and Exchange Server CVE-2026-42897 was added on 15 May with a 29 May Deadline while Microsoft had not yet shipped a fix. The repeat within twelve days reframes the first instance from a one-off forced by exploitation Velocity into a deliberate posture: CISA is willing to set a federal Deadline against a flaw with no available fix.

Common Questions

Reference

What is CISA's Known Exploited Vulnerabilities catalogue?
CISA's KEV catalogue lists CVEs with confirmed active exploitation. Federal agencies must patch KEV CVEs within set deadlines under Binding Operational Directive 22-01. It is the primary public signal of active exploitation used by private-sector patch-prioritisation teams worldwide.Source: CISA
Why did CISA take a month to add the Fortinet FortiSandbox flaw to KEV?
CrowdSec detected in-the-wild exploitation of FortiSandbox CVE-2026-39808 on 17 June 2026, but CISA did not ADD it to the Known Exploited Vulnerabilities catalogue until 16 July, a one-month gap that raises questions about detection-to-listing speed under the new risk-tiered BOD 26-04 model.Source: CrowdSec
Has the pace of new CISA KEV additions slowed down?
Yes. The 5-14 July 2026 window added only seven CVEs, the quietest fortnight tracked, against a roughly two-a-day pace through June, a possible early sign BOD 26-04's risk-tiered triage is changing what gets listed.Source: event
What is the oldest vulnerability in CISA's KEV catalogue?
CVE-2008-4128, an 18-year-old Cisco IOS CSRF flaw, added in the 5-14 July 2026 window, the oldest entry the catalogue has carried since the beat began tracking it.Source: event
Does the CISA KEV catalogue apply to private companies?
BOD 26-04 and its predecessor BOD 22-01 impose mandatory remediation deadlines only on US Federal Civilian Executive Branch agencies. Private-sector organisations are not legally bound but widely treat KEV addition as the strongest available signal of active exploitation.Source: event
How many CVEs are in the CISA Known Exploited Vulnerabilities catalogue?
As of catalogue version 2026.07.29 the KEV catalogue held 1,656 entries, with nothing added between 30 July and 3 August 2026. The growth rate has slowed from the roughly two-a-day pace tracked through June to nearer 0.78 CVEs a day since BOD 26-04's risk-tiered triage took effect on 10 June 2026.Source: event
What replaced BOD 22-01 for CISA KEV patch deadlines?
CISA replaced BOD 22-01 with BOD 26-04 on 10 June 2026. The new directive uses a four-tier risk model (3 days, 14 days, 60 days, or next upgrade cycle) based on exploitability, exposure, asset criticality, and threat actor behaviour.Source: event
What happens when CISA sets a KEV patch deadline before a vendor has shipped a fix?
In May 2026, CISA did this three times in twelve days: PAN-OS CVE-2026-0300 (Deadline 9 May, Palo Alto patches from 13 May), Cisco SD-WAN CVE-2026-20182 (Deadline 17 May), and Exchange CVE-2026-42897 (Deadline 29 May, Microsoft patch not yet shipped). Agencies must implement available mitigations and accept a documented non-compliance posture until the vendor patch ships.Source: CISA KEV / ED 26-03
What was the shortest KEV remediation deadline in 2026?
Three Cisco Catalyst SD-WAN Manager CVEs added to KEV on 20 April 2026 carried a 3-day federal remediation Deadline, the shortest in the April cycle. In May 2026, Cisco SD-WAN CVE-2026-20182 (CVSS 10.0) also carried a 3-day Emergency Directive Deadline from CISA.Source: CISA KEV / April and May 2026
Will CISA budget cuts affect the KEV catalogue?
The Trump administration's FY27 budget proposes cutting CISA by $707m, affecting 860 staff. The KEV catalogue's signal quality and frequency depend on CISA's analyst capacity to monitor exploitation and write advisories. A materially reduced CISA would slow catalogue additions and reduce the advisory detail that private-sector patch teams rely on.Source: CISA budget proposal FY27
Are the vulnerabilities in CISA's KEV catalogue mostly new or old?
A significant share are years old. The June 2026 batch included CVE-2022-0492 (Linux cgroups, four years old) and CVE-2024-21182 (Oracle WebLogic, patched January 2024). A 17-year-old Microsoft Office bug was added in the April 2026 window. KEV is a forcing function across legacy estates, not a zero-day service.Source: CISA KEV
What was the shortest KEV remediation deadline in April 2026?
Three Cisco Catalyst SD-WAN Manager CVEs added to KEV on 20 April 2026 carried a 3-day federal remediation Deadline — the shortest window in the April 2026 additions, signalling CISA's assessment of high active-exploitation risk.Source: CISA KEV / April 2026
Source Material