Reproducible vulnerability research
CISA KEV exposure brief
Current product, severity, and update signals from source-normalized Known Exploited Vulnerability records.
What the current sample shows
Known exploitation is the primary signal: CVSS helps explain technical severity but should not replace CISA remediation due dates, asset exposure, compensating controls, or business criticality.
- high: 56 records
- critical: 32 records
- medium: 12 records
Most frequently represented vendors
- Microsoft — 675 affected-product references
- n/a — 16 affected-product references
- QNAP Systems Inc. — 15 affected-product references
- Cisco — 5 affected-product references
- VMware — 5 affected-product references
- Apache Software Foundation — 3 affected-product references
- Fortinet — 2 affected-product references
- Linux — 2 affected-product references
- SonicWall — 2 affected-product references
- Apple — 1 affected-product references
Counts describe source records, not installed assets or vendor risk. Product naming differences can split or combine labels.
Recently updated KEV records
- CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional... — updated Aug 22, 2026
- CVE-2021-43226: Windows Common Log File System Driver Elevation of Privilege Vulnerability — updated Aug 22, 2026
- CVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability — updated Aug 21, 2026
- CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place — updated Aug 21, 2026
- CVE-2026-64849: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) — updated Aug 20, 2026
- CVE-2026-55040: Microsoft SharePoint Server Security Feature Bypass Vulnerability — updated Aug 20, 2026
- CVE-2026-58644: Microsoft SharePoint Remote Code Execution Vulnerability — updated Aug 20, 2026
- CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability — updated Aug 20, 2026
- CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability — updated Aug 20, 2026
- CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability — updated Aug 20, 2026
- CVE-2022-2586: It was discovered that a nft object or expression could reference a nft set on a different nft table, leadi... — updated Aug 20, 2026
- CVE-2020-1054: Win32k Elevation of Privilege Vulnerability — updated Aug 19, 2026
- CVE-2021-27085: Internet Explorer Remote Code Execution Vulnerability — updated Aug 19, 2026
- CVE-2021-26411: Internet Explorer Memory Corruption Vulnerability — updated Aug 19, 2026
- CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability — updated Aug 19, 2026
Methodology and limitations
- Select published records carrying a normalized CISA KEV signal.
- Order the public query by the library's current relevance and recency behavior and cap the visible aggregate at 100 records.
- Count only explicit normalized severity and affected-vendor fields; missing values are not inferred.
- Link every surfaced record to its source-attributed detail page and preserve CISA/CVE citations.
This brief is not an asset-specific remediation list. Validate affected versions, vendor advisories, CISA due dates, exposure, and compensating controls before prioritizing work.
