⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 8 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2026-94127 F5 BIG-IP APM F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. 9.8 CNA 2026-09-22 2026-09-25 Unknown
CVE-2025-53521 F5 BIG-IP F5 BIG-IP Stack-Based Buffer Overflow Vulnerability F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. 9.8 CNA 2026-03-27 2026-03-30 Unknown
CVE-2023-46747 F5 BIG-IP Configuration Utility F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. 9.8 CNA 2023-10-31 2023-11-21 Known
CVE-2023-46748 F5 BIG-IP Configuration Utility F5 BIG-IP Configuration Utility SQL Injection Vulnerability F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. 8.8 CNA 2023-10-31 2023-11-21 Unknown
CVE-2022-1388 F5 BIG-IP F5 BIG-IP Missing Authentication Vulnerability F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. 9.8 CNA 2022-05-10 2022-05-31 Known
CVE-2021-22991 F5 BIG-IP Traffic Management Microkernel F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. 9.8 CISA 2022-01-18 2022-02-01 Unknown
CVE-2021-22986 F5 BIG-IP and BIG-IQ Centralized Management F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2020-5902 F5 BIG-IP F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. 9.8 CISA 2021-11-03 2022-05-03 Known