KEV required action changed
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Wed 26 Aug 2026· 1 change | ||||
| 2026-08-26 | CVE-2026-21962 | OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable., now states Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Time to revision 2 days |
| Wed 13 May 2026· 1 change | ||||
| 2026-05-13 | CVE-2026-0300 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch. | Time to revision 7 days |
| Tue 5 Aug 2025· 3 changes | ||||
| 2025-08-05 | MicrosoftSharePoint | stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Time to revision 14 days | |
| 2025-08-05 | CVE-2025-49704 | same vendor as the line above | same change as the line above | Time to revision 14 days |
| 2025-08-05 | CVE-2025-49706 | same vendor as the line above | same change as the line above | Time to revision 14 days |
| 2025-08-05 | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | stated at publication CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. , now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Time to revision 15 days |
| Wed 16 Apr 2025· 1 change | ||||
| 2025-04-16 | CVE-2023-44487 | IETFHTTP/2 CISA KEV | stated at publication Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Duration unknown |
| Mon 7 Apr 2025· 1 change | ||||
| 2025-04-07 | CVE-2025-22457 | IvantiConnect Secure, Policy Secure and ZTA Gateways CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable., now states Apply mitigations as set forth in the CISA instructions linked below. | Time to revision 3 days |
| Mon 31 Mar 2025· 2 changes | ||||
| 2025-03-31 | CVE-2025-30154 | reviewdogaction-setup GitHub Action CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable., now states Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Time to revision 7 days |
| 2025-03-31 | CVE-2025-30066 | tj-actionschanged-files GitHub Action CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable., now states Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Time to revision 13 days |
This kind is counted once per CVE record, so changes and records are the same number here. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →