⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 17 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2025-48595 Android Framework Android Framework Integer Overflow Vulnerability Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. 8.4 CISA 2026-06-02 2026-06-05 Unknown
CVE-2025-48572 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation. 7.8 CISA 2025-12-02 2025-12-23 Unknown
CVE-2025-48633 Android Framework Android Framework Information Disclosure Vulnerability Android Framework contains an unspecified vulnerability that allows for information disclosure. 5.5 CISA 2025-12-02 2025-12-23 Unknown
CVE-2025-48543 Android Runtime Android Runtime Use-After-Free Vulnerability Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. 8.8 CISA 2025-09-04 2025-09-25 Unknown
CVE-2024-43093 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation. 7.3 CISA 2024-11-07 2024-11-28 Unknown
CVE-2024-36971 Android Kernel Android Kernel Remote Code Execution Vulnerability Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS. 7.8 CISA 2024-08-07 2024-08-28 Unknown
CVE-2024-32896 Android Pixel Android Pixel Privilege Escalation Vulnerability Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. 8.1 CISA 2024-06-13 2024-07-04 Unknown
CVE-2024-29745 Android Pixel Android Pixel Information Disclosure Vulnerability Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. 5.5 CISA 2024-04-04 2024-04-25 Unknown
CVE-2024-29748 Android Pixel Android Pixel Privilege Escalation Vulnerability Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. 7.8 CISA 2024-04-04 2024-04-25 Unknown
CVE-2023-21237 Android Pixel Android Pixel Information Disclosure Vulnerability Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information. 6.2 CISA 2024-03-05 2024-03-26 Unknown
CVE-2023-35674 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation. 8.8 CISA 2023-09-13 2023-10-04 Unknown
CVE-2023-20963 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. 7.8 CISA 2023-04-13 2023-05-04 Unknown
CVE-2011-1823 Android Android OS Android OS Privilege Escalation Vulnerability The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor. 7.8 CISA 2022-09-08 2022-09-29 Unknown
CVE-2021-0920 Android Kernel Android Kernel Race Condition Vulnerability Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. 6.4 CISA 2022-05-23 2022-06-13 Unknown
CVE-2021-1048 Android Kernel Android Kernel Use-After-Free Vulnerability Android kernel contains a use-after-free vulnerability that allows for privilege escalation. 7.8 CISA 2022-05-23 2022-06-13 Unknown
CVE-2020-0041 Android Android Kernel Android Kernel Out-of-Bounds Write Vulnerability Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2019-2215 Android Android Kernel Android Kernel Use-After-Free Vulnerability Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." 7.8 CISA 2021-11-03 2022-05-03 Unknown