Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Threats and Vulnerabilities

What Is Actually in CISA’s Known Exploited Vulnerabilities Catalog Right Now

Overlooking the CISA KEV catalog means missing clear warnings about vulnerabilities that attackers are already exploiting. This resource highlights real-world threats rather than theoretical risks, giving you evidence that certain weaknesses are actively being used against organizations. For anyone handling IT or compliance at a small or mid-sized business, the catalog offers practical guidance to help you focus your patching and vulnerability management where it matters most.

What is the CISA KEV catalog and what does it include?

The CISA KEV catalog, maintained by the Cybersecurity and Infrastructure Security Agency, is an authoritative list of software and hardware vulnerabilities that have been confirmed as exploited by malicious actors. As of the latest version (catalog version 2026.08.14), the catalog contains 1665 entries. Since January 1, 2026, 181 vulnerabilities have been added, reflecting the ongoing identification of new threats. Of these, 349 are flagged as being used in known ransomware campaigns (CISA Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog).

Each entry in the catalog includes the affected product, a unique CVE identifier, the nature of the vulnerability, and whether it is linked to known ransomware activity. This makes the KEV catalog particularly valuable for organizations that want to focus their resources on patching vulnerabilities that present the greatest actual risk.

How does a vulnerability get added to the CISA KEV catalog?

A vulnerability is only added to the CISA KEV catalog when there is confirmed evidence of exploitation in the wild. This means attackers are more than scanning for these weaknesses but are actively using them to compromise systems. For your organization, this is a signal that a listed vulnerability is more than theoretical or academic: it is a real and present danger.

Which new vulnerabilities with ransomware activity have been added in 2026?

In 2026, several vulnerabilities with known ransomware campaign use have been added to the CISA KEV catalog. These span widely used products and services, including remote access tools, network appliances, collaboration platforms, and operating systems. Here are some examples from the current year with confirmed ransomware exploitation:

  • SonicWall SMA1000 Appliances: Two vulnerabilities (CVE-2026-15409 and CVE-2026-15410) relating to server-side request forgery and code injection.
  • Microsoft SharePoint Server: CVE-2026-45659, a deserialization vulnerability.
  • PTC Windchill and FlexPLM: CVE-2026-12569, improper input validation.
  • Oracle PeopleSoft Enterprise PeopleTools: CVE-2026-35273, missing authentication for a critical function.
  • Palo Alto Networks PAN-OS: CVE-2026-0257, authentication bypass.
  • ConnectWise ScreenConnect: CVE-2024-1708, path traversal vulnerability.
  • Microsoft Defender: CVE-2026-33825, insufficient granularity of access control.
  • Microsoft Windows: CVE-2025-60710, link following vulnerability.
  • Microsoft Exchange Server: CVE-2023-21529, deserialization of untrusted data.

These are only a selection from the 2026 additions with confirmed ransomware campaign use. This highlights that attackers are targeting a wide range of enterprise software, more than niche or legacy products.

How should a small contractor use the CISA KEV catalog?

For small and mid-sized contractors, especially those in regulated industries or handling sensitive data, the KEV catalog is a practical tool for prioritizing patching. Here is how you can use it:

  • Check Your Inventory: Compare the products and versions in your environment against those listed in the CISA KEV catalog.
  • Flag High-Priority Patches: If you find software in your environment with a vulnerability listed in the KEV catalog, treat patching or mitigation as a top priority. These vulnerabilities are being exploited in the wild.
  • Pay Special Attention to Ransomware-Linked Entries: The catalog flags which vulnerabilities are known to be used in ransomware campaigns. If you use any of these products, address these vulnerabilities without delay.
  • Repeat Regularly: The catalog is updated frequently. Make checking it part of your regular vulnerability management process.

Using the KEV catalog as your patch priority list ensures you focus on the vulnerabilities most likely to be targeted by attackers, rather than spreading resources thinly across every possible issue.

What recent vulnerabilities have been added, even if ransomware use is not confirmed?

Not every new addition to the KEV catalog is linked to ransomware, but all are confirmed as exploited. Recent entries (added in July and August 2026) include vulnerabilities in products such as Cisco Secure Firewall, Microsoft Windows Ancillary Function Driver for WinSock, Metabase, Progress LoadMaster, JetBrains TeamCity, N-able N-central, Apache Tomcat, and others. Even if these do not yet have confirmed ransomware use, their presence in the catalog means attackers are using them in the wild.

Where can you find the CISA KEV catalog and how should you use it for compliance?

The CISA KEV catalog is publicly available at CISA’s Known Exploited Vulnerabilities Catalog. The catalog is updated regularly and is considered an authoritative resource by federal agencies and industry. If you are responsible for compliance with frameworks such as NIST 800-171 or the Cybersecurity Maturity Model Certification (CMMC), referencing the KEV catalog can help demonstrate a risk-based approach to patch management and vulnerability remediation.

Common questions

What does it mean if a vulnerability is in the CISA KEV catalog? It means the vulnerability has been confirmed as actively exploited in the wild. Attackers are using it, more than researching or scanning for it.

Do I need to patch every vulnerability in the KEV catalog? You should prioritize patching any KEV-listed vulnerabilities present in your environment, especially those linked to ransomware campaigns. These represent real-world risk.

How often is the CISA KEV catalog updated? The catalog is updated frequently as new exploited vulnerabilities are identified. Regularly reviewing the catalog is recommended.

How Should Defense Contractors Respond Now

If you handle defense contracts or are preparing for NIST 800-171 or CMMC assessment, making the KEV catalog central to your patch management process is essential. For help assessing and closing gaps across all 110 NIST 800-171 controls, qualifying defense contractors can apply for the Cyber Grants Alliance CMMC Gap Assessment Grant. This is an in kind grant delivered as services, designed to help you achieve readiness efficiently. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

At a glance

CISA Known Exploited Vulnerabilities catalog at a glanceCISA Known Exploited Vulnerabilities, catalog 2026.08.141665entries in the catalog181added since 1 January 2026349with known ransomware useInclusion means confirmed exploitation in the wild. Retrieved 2026-08-15.
CISA Known Exploited Vulnerabilities catalog at a glance
How a small team decides what to patch first
How a small team decides what to patch first

More on Threats

Threats · 4 min When Your IT Provider Is the Attack Path

Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.