Skip to content

CISA Known Exploited Vulnerabilities Catalog

Publisher: Cybersecurity and Infrastructure Security AgencyLast checked: 2026-07-21

CISA maintains a searchable catalog with vulnerability identifiers, affected products, required actions for federal agencies, and remediation dates.

Limitations: The catalog is a priority signal, not a complete vulnerability inventory. Product exposure and remediation still need to be verified in each environment.

Why it is useful

CISA maintains a searchable catalog with vulnerability identifiers, affected products, required actions for federal agencies, and remediation dates. This resource is especially useful for Prioritizing vulnerabilities known to be exploited in real attacks. Review the current instructions and limitations from Cybersecurity and Infrastructure Security Agency before relying on it for important work.

Limitations

The catalog is a priority signal, not a complete vulnerability inventory. Product exposure and remediation still need to be verified in each environment.

Visit resource

www.cisa.gov

Report a correction