Every change, newest first
These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Tue 1 Sep 2026· 38 changes | |||||
| 2026-09-01 | Forensic triage now required | CVE-2023-49105 | ownCloudownCloud CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 5 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-53362 | LinuxKernel CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 5 days |
| 2026-09-01 | Forensic triage now required | CVE-2019-1068 | MicrosoftSQL Server CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 6 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-60004 | GiteaGitea CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 7 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-21962 | OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 8 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-73570 | SynacorZimbra Collaboration Suite (ZCS) CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 11 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-72529 | TrueConfServer CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 12 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-59310 | BroadcomVMware vCenter CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 14 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-55040 | MicrosoftSharePoint CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 14 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-65400 | ApplemacOS CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 14 days |
| 2026-09-01 | Forensic triage now required | CVE-2025-62593 | Ray-ProjectRay CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 15 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-72898 | MetabaseMetabase CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 21 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-8037 | ProgressLoadMaster CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 25 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-63077 | JetBrainsTeamCity CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 27 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-18556 | N-ableN-central CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 28 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-9198 | IBMLangflow CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 28 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-18577 | N-ableN-central CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 29 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-16812 | AristaVeloCloud Orchestrator CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 36 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-16232 | Check PointSmartConsole CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 41 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-50522 | MicrosoftSharePoint CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 41 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-63030 | WordPressCore CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 42 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-0770 | LangflowLangflow CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 42 days |
| 2026-09-01 | Forensic triage now required | CVE-2021-27137 | DD-WRTDD-WRT CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 42 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-58644 | MicrosoftSharePoint CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 47 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-25089 | FortinetFortiSandbox CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 47 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-39808 | FortinetFortiSandbox CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 47 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-46817 | OracleE-Business Suite CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 48 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-56164 | MicrosoftSharePoint Server CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 49 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-15409 | SonicWallSMA1000 Appliances CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 49 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-15410 | SonicWallSMA1000 Appliances CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 49 days |
| 2026-09-01 | Forensic triage now required | CVE-2008-4128 | CiscoIOS CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 50 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-56291 | BalbooaForms CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 53 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-48939 | iCagendaiCagenda CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 53 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-48908 | JoomShaperSP Page Builder CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 56 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-55255 | LangflowLangflow CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 56 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-56290 | JoomlackPage Builder CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 56 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-48282 | AdobeColdFusion CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 56 days |
| 2026-09-01 | Forensic triage now required | CVE-2026-45659 | MicrosoftSharePoint Server CISA KEV | stated at publication not stated, now states YesNot counted: The prior instruction already required triage. requiredAction already named CISA's Forensics Triage Requirements; the structured field changed, not the first stated requirement | Time to revision 62 days |
| Fri 21 Aug 2026· 1 change | |||||
| 2026-08-21 | Removed from CISA KEV | CVE-2026-69836 | MicrosoftEntra ID CISA KEV | Previously listed from 2026-08-21Not counted: Same-day catalog correction. entry stood 1.2 hours before being withdrawn — a same-day catalog correction, not a KEV listing anyone escalated | Time to revision 0 days |
| Mon 17 Aug 2026· 1 change | |||||
| 2026-08-17 | KEV due date moved | CVE-2025-62593 | Ray-ProjectRay CISA KEV | stated at publication 2026-08-21, now states 2026-08-20Not counted: Entry date corrected, deadline followed. dateAdded moved 2026-08-18 -> 2026-08-17 in the same commit and the due date moved by the same number of days — the entry date was corrected, the obligation did not move | Time to revision 0 days |
| Thu 29 Jan 2026· 1 change | |||||
| 2026-01-29 | Removed from CISA KEV | CVE-2026-1281 | IvantiEndpoint Manager Mobile (EPMM) CISA KEV | Previously listed from 2026-01-29Not counted: Same-day catalog correction. entry stood 1.0 hours before being withdrawn — a same-day catalog correction, not a KEV listing anyone escalated | Time to revision 0 days |
| Wed 17 Dec 2025· 15 changes | |||||
| 2025-12-17 | KEV due date moved | CVE-2021-34527 | MicrosoftWindows CISA KEV | stated at publication 2021-07-20, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2020-1350 | MicrosoftWindows CISA KEV | stated at publication 2020-07-24, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2020-1472 | MicrosoftNetlogon CISA KEV | stated at publication 2020-09-21, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-26855 | MicrosoftExchange Server CISA KEV | stated at publication 2021-04-16, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-26858 | MicrosoftExchange Server CISA KEV | stated at publication 2021-04-16, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-27065 | MicrosoftExchange Server CISA KEV | stated at publication 2021-04-16, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2020-0601 | MicrosoftWindows CISA KEV | stated at publication 2020-01-29, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-26857 | MicrosoftExchange Server CISA KEV | stated at publication 2021-04-16, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-22893 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2020-8243 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-22900 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-22894 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2020-8260 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2021-22899 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| 2025-12-17 | KEV due date moved | CVE-2019-11510 | IvantiPulse Connect Secure CISA KEV | stated at publication 2021-04-23, now states 2022-05-03Not counted: Due date backfilled into the past. the new due date 2022-05-03 was already in the past on 2025-12-17, so no live compliance date moved | Duration unknown |
| Wed 15 Oct 2025· 1 change | |||||
| 2025-10-15 | KEV due date moved | CVE-2025-54253 | AdobeExperience Manager (AEM) Forms CISA KEV | stated at publication 2025-11-06, now states 2025-11-05Not counted: Entry date corrected, deadline followed. dateAdded moved 2025-10-16 -> 2025-10-15 in the same commit and the due date moved by the same number of days — the entry date was corrected, the obligation did not move | Time to revision 0 days |
| Mon 6 Oct 2025· 1 change | |||||
| 2025-10-06 | KEV due date moved | CVE-2025-61882 | OracleE-Business Suite CISA KEV | stated at publication 2025-10-28, now states 2025-10-27Not counted: Entry date corrected, deadline followed. dateAdded moved 2025-10-07 -> 2025-10-06 in the same commit and the due date moved by the same number of days — the entry date was corrected, the obligation did not move | Time to revision 0 days |
Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →