CISA adds 39 actively exploited vulnerabilities to its KEV catalog in 30 days
CISA added 39 actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in the past 30 days (Sep 5 to Oct 5, 2026). 36 carry a 2026 CVE ID, 3 a 2025 ID. Cisco $CSCO and Citrix had 4 entries each. CISA lists none of the 39 as known to be used in ransomware
CISA added 39 actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in the past 30 days (Sep 5 to Oct 5, 2026). 36 carry a 2026 CVE ID, 3 a 2025 ID. Cisco $CSCO and Citrix had 4 entries each. CISA lists none of the 39 as known to be used in ransomware campaigns. Age in the chart is based on the year in each CVE ID, not the disclosure date. MikroTik, Microsoft $MSFT and the Linux kernel had 3 entries each. The oldest IDs in this batch: CVE-2025-25249 (Fortinet), CVE-2025-39682 and CVE-2025-39964 (Linux kernel).