⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 81 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2009-0927 Adobe Reader and Acrobat Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. 8.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2010-2861 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. 9.8 CISA 2022-03-25 2022-04-15 Known
CVE-2016-4171 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution. 7.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2016-7892 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. 8.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2009-3960 Adobe BlazeDS Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. 6.5 CISA 2022-03-07 2022-09-07 Known
CVE-2013-0625 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. 9.8 CISA 2022-03-07 2022-09-07 Unknown
CVE-2013-0629 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. 7.5 CISA 2022-03-07 2022-09-07 Unknown
CVE-2013-0631 Adobe ColdFusion Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. 7.5 CISA 2022-03-07 2022-09-07 Unknown
CVE-2008-2992 Adobe Acrobat and Reader Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2010-0188 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2011-0611 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2012-1535 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-0632 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. 9.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-0640 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-0641 Adobe Reader Adobe Reader Buffer Overflow Vulnerability A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-3346 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2014-0496 Adobe Reader and Acrobat Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-3043 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-5119 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-7645 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2016-1019 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2016-4117 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2016-7855 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2017-11292 Adobe Flash Player Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2018-15982 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability 7.8 CISA 2022-02-15 2022-08-15 Known
CVE-2022-24086 Adobe Commerce and Magento Open Source Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. 9.8 CNA 2022-02-15 2022-03-01 Unknown
CVE-2018-4878 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. 7.8 CISA 2021-11-03 2022-05-03 Known
CVE-2018-15961 Adobe ColdFusion Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2018-4939 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-28550 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. 9.6 CNA 2021-11-03 2021-11-17 Unknown
CVE-2021-21017 Adobe Acrobat and Reader Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. 8.8 CNA 2021-11-03 2021-11-17 Unknown