⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 388 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2025-49706 Microsoft SharePoint Microsoft SharePoint Improper Authentication Vulnerability Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. 6.5 CNA 2025-07-22 2025-07-23 Known
CVE-2025-49704 Microsoft SharePoint Microsoft SharePoint Code Injection Vulnerability Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. 8.8 CNA 2025-07-22 2025-07-23 Known
CVE-2025-53770 Microsoft SharePoint Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. 9.8 CNA 2025-07-20 2025-07-21 Known
CVE-2025-33053 Microsoft Windows Microsoft Windows External Control of File Name or Path Vulnerability Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files. 8.8 CNA 2025-06-10 2025-07-01 Unknown
CVE-2025-30400 Microsoft Windows Microsoft Windows DWM Core Library Use-After-Free Vulnerability Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. 7.8 CNA 2025-05-13 2025-06-03 Unknown
CVE-2025-32701 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. 7.8 CNA 2025-05-13 2025-06-03 Unknown
CVE-2025-32706 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. 7.8 CNA 2025-05-13 2025-06-03 Unknown
CVE-2025-30397 Microsoft Windows Microsoft Windows Scripting Engine Type Confusion Vulnerability Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. 7.5 CNA 2025-05-13 2025-06-03 Unknown
CVE-2025-32709 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. 7.8 CNA 2025-05-13 2025-06-03 Unknown
CVE-2025-24054 Microsoft Windows Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. 6.5 CNA 2025-04-17 2025-05-08 Unknown
CVE-2025-29824 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. 7.8 CNA 2025-04-08 2025-04-29 Known
CVE-2025-26633 Microsoft Windows Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. 7.0 CNA 2025-03-11 2025-04-01 Known
CVE-2025-24983 Microsoft Windows Microsoft Windows Win32k Use-After-Free Vulnerability Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. 7.0 CNA 2025-03-11 2025-04-01 Unknown
CVE-2025-24984 Microsoft Windows Microsoft Windows NTFS Information Disclosure Vulnerability Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. 4.6 CNA 2025-03-11 2025-04-01 Unknown
CVE-2025-24985 Microsoft Windows Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. 7.8 CNA 2025-03-11 2025-04-01 Unknown
CVE-2025-24991 Microsoft Windows Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. 5.5 CNA 2025-03-11 2025-04-01 Unknown
CVE-2025-24993 Microsoft Windows Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. 7.8 CNA 2025-03-11 2025-04-01 Unknown
CVE-2018-8639 Microsoft Windows Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. 8.4 CISA 2025-03-03 2025-03-24 Known
CVE-2024-49035 Microsoft Partner Center Microsoft Partner Center Improper Access Control Vulnerability Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. 8.7 CNA 2025-02-25 2025-03-18 Unknown
CVE-2025-24989 Microsoft Power Pages Microsoft Power Pages Improper Access Control Vulnerability Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. 8.2 CNA 2025-02-21 2025-03-14 Unknown
CVE-2025-21391 Microsoft Windows Microsoft Windows Storage Link Following Vulnerability Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. 7.1 CNA 2025-02-11 2025-03-04 Unknown
CVE-2025-21418 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-02-11 2025-03-04 Unknown
CVE-2024-21413 Microsoft Office Outlook Microsoft Outlook Improper Input Validation Vulnerability Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. 9.8 CNA 2025-02-06 2025-02-27 Unknown
CVE-2024-29059 Microsoft .NET Framework Microsoft .NET Framework Information Disclosure Vulnerability Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. 7.5 CNA 2025-02-04 2025-02-25 Unknown
CVE-2025-21333 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2025-21334 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2025-21335 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2024-35250 Microsoft Windows Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. 7.8 CNA 2024-12-16 2025-01-06 Unknown
CVE-2024-49138 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. 7.8 CNA 2024-12-10 2024-12-31 Unknown
CVE-2024-49039 Microsoft Windows Microsoft Windows Task Scheduler Privilege Escalation Vulnerability Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. 8.8 CNA 2024-11-12 2024-12-03 Known
CVE-2024-43451 Microsoft Windows Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. 6.5 CNA 2024-11-12 2024-12-03 Unknown
CVE-2024-38094 Microsoft SharePoint Microsoft SharePoint Deserialization Vulnerability Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. 7.2 CNA 2024-10-22 2024-11-12 Known
CVE-2024-30088 Microsoft Windows Microsoft Windows Kernel TOCTOU Race Condition Vulnerability Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. 7.0 CNA 2024-10-15 2024-11-05 Known
CVE-2024-43572 Microsoft Windows Microsoft Windows Management Console Remote Code Execution Vulnerability Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. 7.8 CNA 2024-10-08 2024-10-29 Unknown
CVE-2024-43573 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. 6.5 CNA 2024-10-08 2024-10-29 Unknown
CVE-2020-0618 Microsoft SQL Server Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. 9.8 CISA 2024-09-18 2024-10-09 Known
CVE-2024-43461 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. 8.8 CNA 2024-09-16 2024-10-07 Unknown
CVE-2024-38226 Microsoft Publisher Microsoft Publisher Protection Mechanism Failure Vulnerability Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. 7.3 CNA 2024-09-10 2024-10-01 Unknown
CVE-2024-38014 Microsoft Windows Microsoft Windows Installer Improper Privilege Management Vulnerability Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges. 7.8 CNA 2024-09-10 2024-10-01 Unknown
CVE-2024-38217 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. 5.4 CNA 2024-09-10 2024-10-01 Unknown
CVE-2021-31196 Microsoft Exchange Server Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. 7.2 CNA 2024-08-21 2024-09-11 Unknown
CVE-2024-38189 Microsoft Project Microsoft Project Remote Code Execution Vulnerability Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. 8.8 CNA 2024-08-13 2024-09-03 Unknown
CVE-2024-38178 Microsoft Windows Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. 7.5 CNA 2024-08-13 2024-09-03 Unknown
CVE-2024-38213 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. 6.5 CNA 2024-08-13 2024-09-03 Unknown
CVE-2024-38193 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. 7.8 CNA 2024-08-13 2024-09-03 Unknown
CVE-2024-38106 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. 7.0 CNA 2024-08-13 2024-09-03 Unknown
CVE-2024-38107 Microsoft Windows Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. 7.8 CNA 2024-08-13 2024-09-03 Unknown
CVE-2018-0824 Microsoft Windows Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. 7.5 CISA 2024-08-05 2024-08-26 Unknown
CVE-2012-4792 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. 8.8 CISA 2024-07-23 2024-08-13 Unknown
CVE-2024-38112 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. 7.5 CNA 2024-07-09 2024-07-30 Unknown