#kev — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kev, aggregated by home.social.
-
CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.
-
Small update to the KEV Catalogs page in Vulnerability-Lookup.
More KEV Catalogs:
https://vulnerability.circl.lu/kev-catalogs -
📊 Vulnerability Report — July 2026 is out
https://www.vulnerability-lookup.org/2026/08/14/vulnerability-report-july-2026/
A record of published CVEs (+23% over June) and 61,263 sightings.
4 SharePoint flaws in CISA KEV in 4 weeks, a chained WordPress core pair topping the sightings, and a wave of Joomla extensions.
We put 5 KEV catalogs side by side: 65 vulnerabilities entered at least one in July — watching only CISA would have missed nearly half.
#CTI #KEV #VulnerabilityLookup #VulnerabilityReport #GCVE #CVE #OpenSource #CyberSecurity
-
🚀 Vulnerability-Lookup 6.0.0 is out!
🔔 Webhook notifications — push your product reports to any HTTPS endpoint (chat, SIEM, ticketing), with a configurable payload and a strict outbound policy.
📈 Local exploit hazard — new API endpoints, hazard-ordered reports, and daily standing exposure alerts.
👥 A searchable vulnerability credits index
🧭 SSVC v2.0 decisions on the CVE page👉 https://www.vulnerability-lookup.org/2026/08/13/vulnerability-lookup-6-0-0/
#CVE #EPSS #KEV #GCVE #OpenSource #OpenData #Software #Community #AI #CyberSecurity
-
CISA added three bugs to its KEV list. An N-able N-central authentication bypass is exploited in the wild to deploy RMM tools. Patch by August 7.
#Nable #Ncentral #CISA #KEV #CVE202618556 #ExploitedInTheWild #RMM #Langflow #ApacheTomcat #CyberSecurity #InfoSec
-
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.
KEV confirmed.
-
Here are two emails that landed in my inbox this morning.
Sent by the @circl Vulnerability-Lookup instance, notifying me about new KEV entries in the excellent @shadowserver KEV Catalog and in the #CISA KEV Catalog.The catalogs are available here (including the link to the original sources):
👉 https://vulnerability.circl.lu/kev-catalogs
As well available via API and RSS/Atom!
📬 And email subscriptions are free!
-
CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
#CISA #cybersecurity #infosec #patchnow #vulnerabilitymanagement #KEV
-
A new KEV Catalog built from real-world exploitation data !
We are excited to share the result of a fruitful collaboration with @shadowserver: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.
#ShadowServer #KEV #GCVE #Vulnerability #VulnerabilityManagement #Decentralization #Fragmentation
-
We are improving the KEV Catalogs page of Vulnerability-Lookup.
Just have a look:
👉 https://vulnerability.circl.lu/kev-catalogs
#CyberSecurity #VulnerabilityManagement #Vulnerability #GCVE #CVE #CISA #KEV #ThreatIntel #OpenSource
-
Vulnerability-Lookup now provides a coverage matrix on its KEV catalogs page, showing which Known Exploited Vulnerability catalogs (e.g. EUVD KEV, CISA KEV, CIRCL KEV) reference the most recently updated vulnerabilities. Each row corresponds to a vulnerability and each column to a catalog.
The coverage matrix is available at:
-
Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint
Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать
https://habr.com/ru/companies/pt/articles/1028828/
#vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve
-
Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?
https://thehackernews.com/2026/04/cisa-adds-8-exploited-flaws-to-kev-sets.html
-
gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.
It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.
#cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement
🔗 https://github.com/gcve-eu/gcve-eu-kev
🔗 https://gcve.eu/bcp/gcve-bcp-07/ -
Following a great question from CERT.PL about GCVE KEV assertion format and especially about the confidence level for an evidence of a vulnerability assertion.
We made a first table of confidence level for the evidence in the KEV record format.
#kev #gcve #format #vulnerability #openstandard
🔗 Discussions / Proposal https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744/36?u=adulau
🔗 GCVE BCP-07 https://gcve.eu/bcp/gcve-bcp-07/
-
Exports matter to us. A lot. You’ve been warned 😉
Vulnerability-Lookup now supports KEV catalog export to NDJSON.#OpenData #KEV #CVE #GCVE #Vulnerability #OpenSource #CyberSecurity
-
We’re proud to be included in the VulnCheck State of Exploitation 2026 report and recognized for CrowdSec’s growth as a leading source in first reporting KEVs throughout 2025.
Big thanks to @vulncheck and Patrick Garrity for the recognition, and congrats on the launch of VulnCheck Canary Intelligence.
👉 Read the full article: https://www.vulncheck.com/blog/state-of-exploitation-2026
#threatintelligence #VulnCheck #vulnerability #KEV #cybersecurity @vulncheckai
-
CISA Urges Emergency Patching for Actively Exploited HPE OneView Flaw https://hackread.com/cisa-emergency-patching-exploit-hpe-oneview-flaw/ #HewlettPackardEnterprise #Cybersecurity #Vulnerability #CyberAttack #Security #CISA #HPE #KEV
-
In 2025, the top 5 known exploited vulnerability (#KEV) vendors as of https://cyble.com/blog/cisa-kev-2025-exploited-vulnerabilities-growth/ were:
Microsoft (39)
#Apple (9)
#Cisco (8)
#Fortinet (8)
#Google #Chromium (7)If you like to minimize your #security risk here, avoiding those vendors could improve your overall exposure.
As you can see, this is particularly true for #Microsoft.
Mitigation using #AntiMalware or #EndPointProtection is not the answer as we've learned in the previous year where the "Most Frequently Exploited #Vulnerabilities" have been security products!
Source: https://services.google.com/fh/files/misc/m-trends-2025-en.pdfIf you have high requirements for #ITsecurity, you need to migrate your systems to #Linux which is also part of KEV but on a *much* better level!
-
KEV Assertion Format – Draft Specification (potential BCP?)
This format describes a generic KEV (Known Exploited Vulnerability) assertion format.
The goal is to express who claims exploitation, when, based on what, where it was observed, and with which level of confidence, without turning KEV into full threat intelligence. A KEV assertion is usually very binary and lacking some meta-information. The format adds some information which could better capture details about the exploitation. A majority of the fields are optional except
vulnerability,statusandevidence.[].sourcewhich are recommended.Feedback, ideas, comments more than welcome!
🔗 https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp/744
-
-
Maybe some of you are not aware about the @enisa_eu Known Exploited Vulnerabilities Catalog. In any case, it is now available via Vulnerability-Lookup:
https://vulnerability.circl.lu
and with the API:
https://vulnerability.circl.lu/api