CISA's latest release: 4 October 2026, 18:52 UTC

What attackers exploit, and what to patch first

As of , 1,734 vulnerabilities are on CISA's list of exploited vulnerabilities; CISA added 5 in the last 7 days. Patch first: CVE-2026-85706 in GitLab Community Edition and Enterprise Edition.

Patch first now

Our patch-first order for the entries CISA listed in the last 30 days.

Patch first now
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-85706Path TraversalGitLab Community Edition and Enterprise EditionPatch nowForensic triage required by CISA; Metasploit module0.93
2CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or ChannelCisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementPatch nowForensic triage required by CISA; Metasploit module0.88
3CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
4CVE-2026-87902Remote File InclusionWordPress CorePatch nowForensic triage required by CISA; listed in the last 14 days0.46
5CVE-2026-76461SQL InjectionCisco Secure Email GatewayPatch nowForensic triage required by CISA0.28
6CVE-2026-93616Path TraversalCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.20
7CVE-2026-19490Authentication Bypass Using an Alternate Path or ChannelCitrix NetScalerPatch nowForensic triage required by CISA0.23
8CVE-2026-76460Incorrect Use of Privileged APIsCisco Identity Services EnginePatch nowForensic triage required by CISA0.14
9CVE-2026-86218Static Code InjectionN-able N-centralPatch nowForensic triage required by CISA0.13
10CVE-2026-85102Improper Certificate ValidationCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.08

All 1,734 in patch-first order

Latest additions

Added each month

204060Nov 2024: 22Dec 2024: 16Jan 2025: 14Jan 2025Feb 2025: 27Mar 2025: 32Apr 2025: 15Apr 2025May 2025: 25Jun 2025: 20Jul 2025: 20Jul 2025Aug 2025: 15Sep 2025: 16Oct 2025: 32Oct 2025Nov 2025: 11Dec 2025: 20Jan 2026: 17Jan 2026Feb 2026: 28Mar 2026: 26Apr 2026: 31Apr 2026May 2026: 21Jun 2026: 23Jul 2026: 26Jul 2026Aug 2026: 32Sep 2026: 4343Oct 2026: 44Oct 2026
Entries CISA added to its list in each of the last 24 months. Source: CISA KEV.
Show the numbers
Periodentries added
Nov 202422
Dec 202416
Jan 202514
Feb 202527
Mar 202532
Apr 202515
May 202525
Jun 202520
Jul 202520
Aug 202515
Sep 202516
Oct 202532
Nov 202511
Dec 202520
Jan 202617
Feb 202628
Mar 202626
Apr 202631
May 202621
Jun 202623
Jul 202626
Aug 202632
Sep 202643
Oct 20264

Most exploited vendors in 2026

  1. Microsoft40
  2. Cisco18
  3. Apple9
  4. Fortinet8
  5. Google8
  6. Linux8
  7. Adobe6
  8. Citrix6
  9. Ivanti5
  10. Synacor5
Entries CISA added in 2026, by vendor. Source: CISA KEV.

Changes CISA did not announce

CISA's file keeps only the latest state of each entry. We keep what changed.

  1. CVE-2026-63077 JetBrains TeamCityRansomware use: Unknown to Known.
  2. CVE-2026-86060 MikroTik RouterOSEdited: description.
  3. CVE-2026-86060 MikroTik RouterOSEdited: notes.
  4. CVE-2026-84869 ConnectWise ScreenConnectEdited: description.
  5. CVE-2026-67277 MikroTik RouterOSEdited: description.
  6. CVE-2026-42016 JFrog ArtifactoryEdited: description.
  7. CVE-2026-59310 Broadcom VMware vCenterRansomware use: Unknown to Known.
  8. CVE-2026-20316 Cisco Secure Firewall Management Center (FMC)Ransomware use: Unknown to Known.
  9. CVE-2022-41352 Synacor Zimbra Collaboration Suite (ZCS)Ransomware use: Unknown to Known.
  10. CVE-2019-0859 Microsoft Win32kRansomware use: Unknown to Known.

Every change we recorded

Where EPSS and CISA disagree