⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 15 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2026-0257 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. 7.8 CNA 2026-05-29 2026-06-01 Known
CVE-2026-0300 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. 9.3 CNA 2026-05-06 2026-05-09 Unknown
CVE-2025-0111 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS File Read Vulnerability Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. 7.1 CNA 2025-02-20 2025-03-13 Unknown
CVE-2025-0108 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts. 8.8 CNA 2025-02-18 2025-03-11 Unknown
CVE-2024-3393 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. 8.7 CNA 2024-12-30 2025-01-20 Unknown
CVE-2024-0012 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. 9.3 CNA 2024-11-18 2024-12-09 Known
CVE-2024-9474 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. 6.9 CNA 2024-11-18 2024-12-09 Known
CVE-2024-9463 Palo Alto Networks Expedition Palo Alto Networks Expedition OS Command Injection Vulnerability Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. 9.9 CNA 2024-11-14 2024-12-05 Unknown
CVE-2024-9465 Palo Alto Networks Expedition Palo Alto Networks Expedition SQL Injection Vulnerability Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. 9.2 CNA 2024-11-14 2024-12-05 Unknown
CVE-2024-5910 Palo Alto Networks Expedition Palo Alto Networks Expedition Missing Authentication Vulnerability Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data. 9.3 CNA 2024-11-07 2024-11-28 Unknown
CVE-2024-3400 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Command Injection Vulnerability Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. 10.0 CNA 2024-04-12 2024-04-19 Known
CVE-2022-0028 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. 8.6 CNA 2022-08-22 2022-09-12 Unknown
CVE-2017-15944 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. 9.8 CISA 2022-08-18 2022-09-08 Unknown
CVE-2020-2021 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. 10.0 CNA 2022-03-25 2022-04-15 Known
CVE-2019-1579 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. 8.1 CISA 2022-01-10 2022-07-10 Known