Added to CISA KEV
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Tue 11 Aug 2026· 1 record change | ||||
| 2026-08-11 | CVE-2026-20349 | CiscoSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) CISA KEV | fix due 2026-08-14 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 29 Jul 2026· 1 record change | ||||
| 2026-07-29 | CVE-2026-20316 | CiscoSecure Firewall Management Center (FMC) CISA KEV | fix due 2026-08-01 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 13 Jul 2026· 1 record change | ||||
| 2026-07-13 | CVE-2008-4128 | CiscoIOS CISA KEV | fix due 2026-07-16 | Not applicable: Added to CISA KEV has no earlier value |
| Thu 25 Jun 2026· 1 record change | ||||
| 2026-06-25 | CVE-2026-20230 | CiscoUnified Communications Manager CISA KEV | fix due 2026-06-28 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 15 Jun 2026· 1 record change | ||||
| 2026-06-15 | CVE-2026-20262 | CiscoCatalyst SD-WAN Manager CISA KEV | fix due 2026-06-29 | Not applicable: Added to CISA KEV has no earlier value |
| Tue 9 Jun 2026· 1 record change | ||||
| 2026-06-09 | CVE-2026-20245 | CiscoCatalyst SD-WAN Manager CISA KEV | fix due 2026-06-23 | Not applicable: Added to CISA KEV has no earlier value |
| Thu 14 May 2026· 1 record change | ||||
| 2026-05-14 | CVE-2026-20182 | CiscoCatalyst SD-WAN CISA KEV | fix due 2026-05-17 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 20 Apr 2026· 3 record changes | ||||
| 2026-04-20 | CVE-2026-20122 | CiscoCatalyst SD-WAN Manger CISA KEV | fix due 2026-04-23 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | CiscoCatalyst SD-WAN Manager | fix due 2026-04-23 | Not applicable: Added to CISA KEV has no earlier value | |
| 2026-04-20 | CVE-2026-20133 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | CVE-2026-20128 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| Thu 19 Mar 2026· 1 record change | ||||
| 2026-03-19 | CVE-2026-20131 | CiscoSecure Firewall Management Center (FMC) CISA KEV | fix due 2026-03-22 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 25 Feb 2026· 2 record changes | ||||
| 2026-02-25 | CVE-2022-20775 | CiscoSD-WAN CISA KEV | fix due 2026-02-27 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-02-25 | CVE-2026-20127 | CiscoCatalyst SD-WAN Controller and Manager CISA KEV | fix due 2026-02-27 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 21 Jan 2026· 1 record change | ||||
| 2026-01-21 | CVE-2026-20045 | CiscoUnified Communications Manager CISA KEV | fix due 2026-02-11 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 17 Dec 2025· 1 record change | ||||
| 2025-12-17 | CVE-2025-20393 | CiscoMultiple Products CISA KEV | fix due 2025-12-24 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 29 Sep 2025· 1 record change | ||||
| 2025-09-29 | CVE-2025-20352 | CiscoIOS and IOS XE CISA KEV | fix due 2025-10-20 | Not applicable: Added to CISA KEV has no earlier value |
| Thu 25 Sep 2025· 2 record changes | ||||
| 2025-09-25 | CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | fix due 2025-09-26 | Not applicable: Added to CISA KEV has no earlier value | |
| 2025-09-25 | CVE-2025-20362 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2025-09-25 | CVE-2025-20333 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| Mon 28 Jul 2025· 2 record changes | ||||
| 2025-07-28 | CiscoIdentity Services Engine | fix due 2025-08-18 | Not applicable: Added to CISA KEV has no earlier value | |
| 2025-07-28 | CVE-2025-20337 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2025-07-28 | CVE-2025-20281 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| Mon 31 Mar 2025· 1 record change | ||||
| 2025-03-31 | CVE-2024-20439 | CiscoSmart Licensing Utility CISA KEV | fix due 2025-04-21 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 3 Mar 2025· 1 record change | ||||
| 2025-03-03 | CVE-2023-20118 | CiscoSmall Business RV Series Routers CISA KEV | fix due 2025-03-24 | Not applicable: Added to CISA KEV has no earlier value |
This kind is counted once per CVE record, so changes and records are the same number here. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →