⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 31 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2025-39682 Linux Kernel Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. 9.8 CNA 2026-09-18 2026-09-21 Unknown
CVE-2026-53266 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. 8.8 CNA 2026-09-18 2026-09-21 Unknown
CVE-2025-39964 Linux Kernel Linux Kernel Race Condition Vulnerability Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. 7.8 CNA 2026-09-18 2026-09-21 Unknown
CVE-2026-53362 Linux Kernel Linux Kernel Unspecified Vulnerability Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. 7.8 CNA 2026-08-27 2026-08-30 Unknown
CVE-2022-0995 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. 7.8 CISA 2026-08-26 2026-09-09 Unknown
CVE-2022-0492 Linux Kernel Linux Kernel Improper Authentication Vulnerability Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. 7.8 CISA 2026-06-02 2026-06-05 Unknown
CVE-2026-31431 Linux Kernel Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. 7.8 CNA 2026-05-01 2026-05-15 Unknown
CVE-2018-14634 Linux Kernel Linux Kernel Integer Overflow Vulnerability Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system. 7.8 CNA 2026-01-26 2026-02-16 Unknown
CVE-2021-22555 Linux Kernel Linux Kernel Heap Out-of-Bounds Write Vulnerability Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. 8.3 CNA 2025-10-06 2025-10-27 Unknown
CVE-2025-38352 Linux Kernel Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. 7.4 CISA 2025-09-04 2025-09-25 Unknown
CVE-2023-0386 Linux Kernel Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. 7.8 CISA 2025-06-17 2025-07-08 Unknown
CVE-2024-53197 Linux Kernel Linux Kernel Out-of-Bounds Access Vulnerability Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code. 7.8 CISA 2025-04-09 2025-04-30 Unknown
CVE-2024-53150 Linux Kernel Linux Kernel Out-of-Bounds Read Vulnerability Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information. 7.1 CISA 2025-04-09 2025-04-30 Unknown
CVE-2024-50302 Linux Kernel Linux Kernel Use of Uninitialized Resource Vulnerability The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. 5.5 CISA 2025-03-04 2025-03-25 Unknown
CVE-2024-53104 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. 7.8 CISA 2025-02-05 2025-02-26 Unknown
CVE-2017-1000253 Linux Kernel Linux Kernel PIE Stack Buffer Corruption Vulnerability Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. 7.8 CISA 2024-09-09 2024-09-30 Known
CVE-2022-0185 Linux Kernel Linux Kernel Heap-Based Buffer Overflow Vulnerability Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges. 8.4 CISA 2024-08-21 2024-09-11 Unknown
CVE-2022-2586 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges. 5.3 CNA 2024-06-26 2024-07-17 Unknown
CVE-2024-1086 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. 7.8 CNA 2024-05-30 2024-06-20 Known
CVE-2010-3904 Linux Kernel Linux Kernel Improper Input Validation Vulnerability Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. 7.8 CISA 2023-05-12 2023-06-02 Unknown
CVE-2014-0196 Linux Kernel Linux Kernel Race Condition Vulnerability Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. 5.5 CISA 2023-05-12 2023-06-02 Unknown
CVE-2023-0266 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. 7.9 CNA 2023-03-30 2023-04-20 Unknown
CVE-2021-3493 Linux Kernel Linux Kernel Privilege Escalation Vulnerability The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. 8.8 CNA 2022-10-20 2022-11-10 Unknown
CVE-2013-2094 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation. 8.4 CISA 2022-09-15 2022-10-06 Unknown
CVE-2013-2596 Linux Kernel Linux Kernel Integer Overflow Vulnerability Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. 7.8 CISA 2022-09-15 2022-10-06 Unknown
CVE-2013-6282 Linux Kernel Linux Kernel Improper Input Validation Vulnerability The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. 8.8 CISA 2022-09-15 2022-10-06 Unknown
CVE-2014-3153 Linux Kernel Linux Kernel Privilege Escalation Vulnerability The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. 7.8 CISA 2022-05-25 2022-06-15 Unknown
CVE-2022-0847 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." 7.8 CISA 2022-04-25 2022-05-16 Unknown
CVE-2021-22600 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. 6.6 CNA 2022-04-11 2022-05-02 Unknown
CVE-2016-5195 Linux Kernel Linux Kernel Race Condition Vulnerability Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. 7.0 CISA 2022-03-03 2022-03-24 Unknown
CVE-2019-13272 Linux Kernel Linux Kernel Improper Privilege Management Vulnerability Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. 7.8 CISA 2021-12-10 2022-06-10 Unknown