cisa-kev
CISA KEVExtracts: CVE id, vendor, due date · metadata or bounded excerpt
Retention: D1 event history with canonical source link and deduplication metadata.
Access basis: Public endpoint; no project credential required.
Last ingested: 2026-08-25 · run status: success with data
CVE: CVE-2026-65400 Vendor/project: Apple Product: macOS Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-287 Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without va
CVE: CVE-2026-55040 Vendor/project: Microsoft Product: SharePoint Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-1390 Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a
- 2026-08-18CISA KEV: Broadcom / VMware vCenter / Broadcom VMware vCenter Path Traversal Vulnerability
CVE: CVE-2026-59310 Vendor/project: Broadcom Product: VMware vCenter Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-22 Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute
CVE: CVE-2026-33824 Vendor/project: Microsoft Product: Internet Key Exchange (IKE) Service Extensions Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-415 Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could