⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 388 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2020-1350 Microsoft Windows Microsoft Windows DNS Server Remote Code Execution Vulnerability Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. 10.0 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-28310 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2020-1040 Microsoft Hyper-V RemoteFX Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. 9.0 CISA 2021-11-03 2022-05-03 Unknown
CVE-2019-0803 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. 7.8 CISA 2021-11-03 2022-05-03 Known
CVE-2021-31207 Microsoft Exchange Server Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. 6.6 CNA 2021-11-03 2021-11-17 Known
CVE-2021-34527 Microsoft Windows Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. 8.8 CNA 2021-11-03 2022-05-03 Known
CVE-2021-1732 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2021-11-17 Known
CVE-2020-1464 Microsoft Windows Microsoft Windows Spoofing Vulnerability Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. 7.8 CNA 2021-11-03 2022-05-03 Unknown
CVE-2021-34473 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. 9.1 CNA 2021-11-03 2021-11-17 Known
CVE-2019-0708 Microsoft Remote Desktop Services Microsoft Remote Desktop Services Remote Code Execution Vulnerability Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. 9.8 CISA 2021-11-03 2022-05-03 Known
CVE-2016-7255 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. 7.8 CISA 2021-11-03 2022-05-03 Known
CVE-2017-0143 Microsoft Windows Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. 8.8 CISA 2021-11-03 2022-05-03 Known
CVE-2020-0688 Microsoft Exchange Server Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. 8.8 CISA 2021-11-03 2022-05-03 Known
CVE-2021-38649 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. 7.0 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-36948 Microsoft Windows Microsoft Windows Update Medic Service Privilege Escalation Vulnerability Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2017-7269 Microsoft Internet Information Services (IIS) Microsoft Windows Server Buffer Overflow Vulnerability Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-34523 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. 9.0 CNA 2021-11-03 2021-11-17 Known
CVE-2021-38645 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2020-1020 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. 8.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-0986 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-17144 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. 8.4 CNA 2021-11-03 2022-05-03 Unknown
CVE-2020-0938 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-31979 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 7.8 CISA 2021-11-03 2021-11-17 Unknown
CVE-2021-31201 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. 5.2 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-31956 Microsoft Windows Microsoft Windows NTFS Privilege Escalation Vulnerability Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-33771 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-31199 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. 5.2 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-33742 Microsoft Windows Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. 7.5 CNA 2021-11-03 2021-11-17 Unknown
CVE-2020-17087 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2021-11-03 2022-05-03 Unknown
CVE-2020-0683 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2016-0185 Microsoft Windows Microsoft Windows Media Center Remote Code Execution Vulnerability Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-33739 Microsoft Windows Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. 8.4 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-1647 Microsoft Defender Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. 7.8 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-31955 Microsoft Windows Microsoft Windows Kernel Information Disclosure Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. 5.5 CNA 2021-11-03 2021-11-17 Unknown
CVE-2020-0878 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Memory Corruption Vulnerability Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. 4.2 CNA 2021-11-03 2022-05-03 Known
CVE-2016-0167 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application 7.8 CISA 2021-11-03 2022-05-03 Known
CVE-2021-38647 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. 9.8 CNA 2021-11-03 2021-11-17 Known
CVE-2014-1812 Microsoft Windows Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. 8.8 CISA 2021-11-03 2022-05-03 Known