Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

51 changes · newest first · grouped by dayCSVJSONRSS

SinceClear all
ChangedSourceRows
Counted changes from the last 30 days, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 4 Sep 2026· 3 changes
2026-09-04Added to CISA KEVCVE-2026-85046
GoogleChromium V8
CISA KEV
fix due 2026-09-18Duration unknown
2026-09-04Ransomware use confirmedCVE-2022-37969
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-09-04Ransomware use confirmedCVE-2016-4117
AdobeFlash Player
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
Wed 2 Sep 2026· 7 changes
2026-09-02Added to CISA KEVCVE-2026-59822
BerriAILiteLLM
CISA KEV
fix due 2026-09-16Duration unknown
2026-09-02Added to CISA KEVCVE-2026-48710
KludexStarlette
CISA KEV
fix due 2026-09-16Duration unknown
2026-09-02Added to CISA KEVCVE-2026-49869
KestraKestra OSS
CISA KEV
fix due 2026-09-05Duration unknown
2026-09-02Added to CISA KEVCVE-2026-82329
JFrogArtifactory
CISA KEV
fix due 2026-09-05Duration unknown
2026-09-02Added to CISA KEVCVE-2026-9586
SangomaSwitchvox
CISA KEV
fix due 2026-09-05Duration unknown
2026-09-02Added to CISA KEV
SonicWallSMA1000 Appliances
fix due 2026-09-05Duration unknown
2026-09-02same kind of change as the line aboveCVE-2026-83548same vendor as the line abovesame change as the line aboveDuration unknown
2026-09-02same kind of change as the line aboveCVE-2026-83549same vendor as the line abovesame change as the line aboveDuration unknown
Mon 31 Aug 2026· 2 changes
2026-08-31Added to CISA KEV
PaperCutNG/MF
fix due 2026-09-14Duration unknown
2026-08-31same kind of change as the line aboveCVE-2026-82078same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-31same kind of change as the line aboveCVE-2026-81578same vendor as the line abovesame change as the line aboveDuration unknown
Fri 28 Aug 2026· 3 changes
2026-08-28Added to CISA KEVCVE-2023-49105
ownCloudownCloud
CISA KEV
fix due 2026-08-30 · listed 2026-08-27Duration unknown
2026-08-28Added to CISA KEVCVE-2026-53362
LinuxKernel
CISA KEV
fix due 2026-08-30 · listed 2026-08-27Duration unknown
2026-08-28Added to CISA KEVCVE-2026-66384
JFrogArtifactory
CISA KEV
fix due 2026-09-10 · listed 2026-08-27Duration unknown
Wed 26 Aug 2026· 7 changes
2026-08-26Added to CISA KEVCVE-2021-23758
Ajax.NET ProfessionalAjax.NET Professional
CISA KEV
fix due 2026-09-09Duration unknown
2026-08-26Added to CISA KEVCVE-2015-3246
Red HatLibuser
CISA KEV
fix due 2026-09-09Duration unknown
2026-08-26Added to CISA KEVCVE-2015-5287
Red HatAutomatic Bug Reporting Tool
CISA KEV
fix due 2026-09-09Duration unknown
2026-08-26Added to CISA KEVCVE-2022-0995
LinuxKernel
CISA KEV
fix due 2026-09-09Duration unknown
2026-08-26Added to CISA KEVCVE-2026-8452
CitrixNetScaler ADC and NetScaler Gateway
CISA KEV
fix due 2026-08-29Duration unknown
2026-08-26Added to CISA KEVCVE-2019-1068
MicrosoftSQL Server
CISA KEV
fix due 2026-08-29Duration unknown
2026-08-26KEV required action changedCVE-2026-21962
OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in
CISA KEV
stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable., now states Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.Time to revision 2 days
Tue 25 Aug 2026· 1 change
2026-08-25Added to CISA KEVCVE-2026-60004
GiteaGitea
CISA KEV
fix due 2026-08-28Duration unknown
Mon 24 Aug 2026· 1 change
2026-08-24Added to CISA KEVCVE-2026-21962
OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in
CISA KEV
fix due 2026-08-27Duration unknown
Fri 21 Aug 2026· 5 changes
2026-08-21Added to CISA KEVCVE-2026-69836
MicrosoftEntra ID
CISA KEV
fix due 2026-08-24Duration unknown
2026-08-21Added to CISA KEVCVE-2026-73570
SynacorZimbra Collaboration Suite (ZCS)
CISA KEV
fix due 2026-08-24Duration unknown
2026-08-21Ransomware use confirmedCVE-2021-43226
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownTime to revision 319 days
2026-08-21Ransomware use confirmedCVE-2020-5135
SonicWallSonicOS
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-08-21Ransomware use confirmedCVE-2012-0158
MicrosoftMSCOMCTL.OCX
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
Thu 20 Aug 2026· 2 changes
2026-08-20Added to CISA KEV
TrueConfServer
fix due 2026-09-03Duration unknown
2026-08-20same kind of change as the line aboveCVE-2026-72530same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-20same kind of change as the line aboveCVE-2026-72529same vendor as the line abovesame change as the line aboveDuration unknown
Wed 19 Aug 2026· 1 change
2026-08-19Added to CISA KEVCVE-2026-64849
MLflowMLflow
CISA KEV
fix due 2026-09-02Duration unknown
Tue 18 Aug 2026· 4 changes
2026-08-18Added to CISA KEVCVE-2026-33824
MicrosoftInternet Key Exchange (IKE) Service Extensions
CISA KEV
fix due 2026-08-21Duration unknown
2026-08-18Added to CISA KEVCVE-2026-59310
BroadcomVMware vCenter
CISA KEV
fix due 2026-08-21Duration unknown
2026-08-18Added to CISA KEVCVE-2026-55040
MicrosoftSharePoint
CISA KEV
fix due 2026-08-21Duration unknown
2026-08-18Added to CISA KEVCVE-2026-65400
ApplemacOS
CISA KEV
fix due 2026-08-21Duration unknown
Mon 17 Aug 2026· 1 change
2026-08-17Added to CISA KEVCVE-2025-62593CISA KEVfix due 2026-08-21 · listed 2026-08-18Duration unknown
Fri 14 Aug 2026· 10 changes
2026-08-14Ransomware use confirmedCVE-2025-60710
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownTime to revision 123 days
2026-08-14Ransomware use confirmedCVE-2020-29574
SophosCyberoamOS
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-08-14Ransomware use confirmedCVE-2020-0618
MicrosoftSQL Server
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-08-14Ransomware use confirmedCVE-2021-4034
Red HatPolkit
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-08-14Ransomware use confirmed
MicrosoftInternet Explorer
stated at publication Unknown, now states KnownDuration unknown
2026-08-14same kind of change as the line aboveCVE-2016-0189same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-14same kind of change as the line aboveCVE-2020-0968same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-14Ransomware use confirmed
MicrosoftWin32k
stated at publication Unknown, now states KnownDuration unknown
2026-08-14same kind of change as the line aboveCVE-2022-21882same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-14same kind of change as the line aboveCVE-2019-0803same vendor as the line abovesame change as the line aboveDuration unknown
2026-08-14Ransomware use confirmedCVE-2019-5591
FortinetFortiOS
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-08-14Ransomware use confirmedCVE-2018-0802
MicrosoftOffice
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
Tue 11 Aug 2026· 3 changes
2026-08-11Added to CISA KEVCVE-2026-20349
CiscoSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CISA KEV
fix due 2026-08-14Duration unknown
2026-08-11Added to CISA KEVCVE-2026-68820
MicrosoftWindows Ancillary Function Driver for WinSock
CISA KEV
fix due 2026-08-25Duration unknown
2026-08-11Added to CISA KEVCVE-2026-72898
MetabaseMetabase
CISA KEV
fix due 2026-08-14Duration unknown
Mon 10 Aug 2026· 1 change
2026-08-10Ransomware use confirmedCVE-2026-45659
MicrosoftSharePoint Server
CISA KEV
stated at publication Unknown, now states KnownTime to revision 40 days

Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →