CISA Known Exploited Vulnerability Catalog - April 2026

Threat Digest
Download Now

For a detailed CISA's KEV Catalog, download the pdf file here



Summary

The Known Exploited Vulnerability (KEV) catalog, maintained by CISA, is the authoritative source of vulnerabilities that have been exploited in the wild.

It is recommended that all organizations review and monitor the KEV catalog, prioritize remediation of listed vulnerabilities, and reduce the likelihood of compromise by threat actors. In April 2026, 31 vulnerabilities met the criteria for inclusion in the CISA's KEV catalog. Of these, 6 are zero-day vulnerabilities; 10 have been exploited by a threat actor and employed in attacks.