⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 40 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2026-34486 Apache Tomcat Apache Tomcat Missing Encryption of Sensitive Data Vulnerability Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. 7.5 CISA 2026-08-04 2026-08-07 Unknown
CVE-2026-34197 Apache ActiveMQ Apache ActiveMQ Improper Input Validation Vulnerability Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. 8.8 CISA 2026-04-16 2026-04-30 Unknown
CVE-2024-38475 Apache HTTP Server Apache HTTP Server Improper Escaping of Output Vulnerability Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. 9.1 CISA 2025-05-01 2025-05-22 Unknown
CVE-2025-24813 Apache Tomcat Apache Tomcat Path Equivalence Vulnerability Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486. 10.0 CISA 2025-04-01 2025-04-22 Unknown
CVE-2024-45195 Apache OFBiz Apache OFBiz Forced Browsing Vulnerability Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. 9.8 CISA 2025-02-04 2025-02-25 Unknown
CVE-2024-27348 Apache HugeGraph-Server Apache HugeGraph-Server Improper Access Control Vulnerability Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. 9.8 CISA 2024-09-18 2024-10-09 Unknown
CVE-2024-38856 Apache OFBiz Apache OFBiz Incorrect Authorization Vulnerability Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. 8.1 CISA 2024-08-27 2024-09-17 Unknown
CVE-2024-32113 Apache OFBiz Apache OFBiz Path Traversal Vulnerability Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. 9.1 CISA 2024-08-07 2024-08-28 Unknown
CVE-2020-17519 Apache Flink Apache Flink Improper Access Control Vulnerability Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. 9.1 CISA 2024-05-23 2024-06-13 Unknown
CVE-2023-27524 Apache Superset Apache Superset Insecure Default Initialization of Resource Vulnerability Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. 8.9 CNA 2024-01-08 2024-01-29 Unknown
CVE-2023-46604 Apache ActiveMQ Apache ActiveMQ Deserialization of Untrusted Data Vulnerability Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. 10.0 CNA 2023-11-02 2023-11-23 Known
CVE-2023-33246 Apache RocketMQ Apache RocketMQ Command Execution Vulnerability Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. 9.8 CISA 2023-09-06 2023-09-27 Unknown
CVE-2016-8735 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. 9.8 CISA 2023-05-12 2023-06-02 Unknown
CVE-2021-45046 Apache Log4j2 Apache Log4j2 Deserialization of Untrusted Data Vulnerability Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. 9.0 CISA 2023-05-01 2023-05-22 Known
CVE-2022-33891 Apache Spark Apache Spark Command Injection Vulnerability Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. 8.8 CISA 2023-03-07 2023-03-28 Unknown
CVE-2022-24112 Apache APISIX Apache APISIX Authentication Bypass Vulnerability Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution. 9.8 CISA 2022-08-25 2022-09-15 Unknown
CVE-2022-24706 Apache CouchDB Apache CouchDB Insecure Default Initialization of Resource Vulnerability Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges. 9.8 CISA 2022-08-25 2022-09-15 Unknown
CVE-2013-2251 Apache Struts Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. 9.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2017-12615 Apache Tomcat Apache Tomcat on Windows Remote Code Execution Vulnerability When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. 8.1 CISA 2022-03-25 2022-04-15 Known
CVE-2017-12617 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. 8.1 CISA 2022-03-25 2022-04-15 Unknown
CVE-2020-1956 Apache Kylin Apache Kylin OS Command Injection Vulnerability Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. 8.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2020-1938 Apache Tomcat Apache Tomcat Improper Privilege Management Vulnerability Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. 9.8 CISA 2022-03-03 2022-03-17 Unknown
CVE-2016-3088 Apache ActiveMQ Apache ActiveMQ Improper Input Validation Vulnerability The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request 9.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2017-9791 Apache Struts 1 Apache Struts 1 Improper Input Validation Vulnerability The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. 9.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2012-0391 Apache Struts 2 Apache Struts 2 Improper Input Validation Vulnerability The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. 9.8 CISA 2022-01-21 2022-07-21 Unknown
CVE-2006-1547 Apache Struts 1 Apache Struts 1 ActionForm Denial-of-Service Vulnerability ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). 7.5 CISA 2022-01-21 2022-07-21 Unknown
CVE-2020-13927 Apache Airflow's Experimental API Apache Airflow's Experimental API Authentication Bypass The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. 9.8 CISA 2022-01-18 2022-07-18 Unknown
CVE-2020-11978 Apache Airflow Apache Airflow Command Injection A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. 8.8 CISA 2022-01-18 2022-07-18 Unknown
CVE-2021-44228 Apache Log4j2 Apache Log4j2 Remote Code Execution Vulnerability Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. 10.0 CISA 2021-12-10 2021-12-24 Known
CVE-2019-0193 Apache Solr Apache Solr DataImportHandler Code Injection Vulnerability The optional Apache Solr module DataImportHandler contains a code injection vulnerability. 7.2 CISA 2021-12-10 2022-06-10 Unknown
CVE-2021-40438 Apache Apache Apache HTTP Server-Side Request Forgery (SSRF) A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. 9.0 CISA 2021-12-01 2021-12-15 Known
CVE-2018-11776 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. 8.1 CISA 2021-11-03 2022-05-03 Unknown
CVE-2017-5638 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Known
CVE-2020-17530 Apache Struts Apache Struts Remote Code Execution Vulnerability Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2019-17558 Apache Solr Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. 7.5 CISA 2021-11-03 2022-05-03 Unknown
CVE-2016-4437 Apache Shiro Apache Shiro Code Execution Vulnerability Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2019-0211 Apache HTTP Server Apache HTTP Server Privilege Escalation Vulnerability Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-41773 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. 7.5 CISA 2021-11-03 2021-11-17 Known
CVE-2021-42013 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2017-9805 Apache Struts Apache Struts Deserialization of Untrusted Data Vulnerability Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. 8.1 CISA 2021-11-03 2022-05-03 Unknown