The CISA KEV catalog lists 1665 exploited vulnerabilities, including threats with confirmed ransomware use. Learn how to use it to prioritize patching.
Section
Threats and Vulnerabilities
What attackers are exploiting right now, grounded in the CISA Known Exploited Vulnerabilities catalog.
All articles
10 piecesLearn which ransomware vulnerabilities are actively used in attacks, with real CVEs, vendors, and dates based on the CISA Known Exploited Vulnerabilities Catalog.
Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.
The SonicWall vulnerability, flagged for ransomware use, highlights why remote access appliances demand urgent attention from small businesses.
Learn about the SharePoint vulnerability CVE-2026-45659, its ransomware use, and why on-premises collaboration servers pose scoping and security risks.
Firewall vulnerability is a real risk for any business. Learn what recent exploited firewall vulnerabilities mean for your patching and compliance.
Small business ransomware threats target familiar products like cPanel and WordPress. Learn what matters most for your company’s risk and compliance.
Attackers keep using the same legacy vulnerability year after year. Learn why asset inventory is your best defense against old, still-exploited bugs.
Patch management is critical for compliance and risk reduction. Learn how small teams can prioritize using the KEV Catalog and meet SI.L2-3.14.1 requirements.
Credential theft remains the most cost-effective attack method. Learn what IA.L2-3.5.3 requires and how to protect your business from stolen credentials.