Every change, newest first
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Fri 4 Sep 2026· 1 change | |||||
| 2026-09-04 | Ransomware use confirmed | CVE-2022-37969 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Wed 26 Aug 2026· 1 change | |||||
| 2026-08-26 | Added to CISA KEV | CVE-2019-1068 | MicrosoftSQL Server CISA KEV | fix due 2026-08-29 | Duration unknown |
| Fri 21 Aug 2026· 3 changes | |||||
| 2026-08-21 | Added to CISA KEV | CVE-2026-69836 | MicrosoftEntra ID CISA KEV | fix due 2026-08-24 | Duration unknown |
| 2026-08-21 | Ransomware use confirmed | CVE-2021-43226 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Time to revision 319 days |
| 2026-08-21 | Ransomware use confirmed | CVE-2012-0158 | MicrosoftMSCOMCTL.OCX CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Tue 18 Aug 2026· 2 changes | |||||
| 2026-08-18 | Added to CISA KEV | CVE-2026-33824 | MicrosoftInternet Key Exchange (IKE) Service Extensions CISA KEV | fix due 2026-08-21 | Duration unknown |
| 2026-08-18 | Added to CISA KEV | CVE-2026-55040 | MicrosoftSharePoint CISA KEV | fix due 2026-08-21 | Duration unknown |
| Fri 14 Aug 2026· 7 changes | |||||
| 2026-08-14 | Ransomware use confirmed | CVE-2025-60710 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Time to revision 123 days |
| 2026-08-14 | Ransomware use confirmed | CVE-2020-0618 | MicrosoftSQL Server CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| 2026-08-14 | Ransomware use confirmed | MicrosoftInternet Explorer | stated at publication Unknown, now states Known | Duration unknown | |
| 2026-08-14 | same kind of change as the line above | CVE-2016-0189 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-08-14 | same kind of change as the line above | CVE-2020-0968 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-08-14 | Ransomware use confirmed | MicrosoftWin32k | stated at publication Unknown, now states Known | Duration unknown | |
| 2026-08-14 | same kind of change as the line above | CVE-2022-21882 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-08-14 | same kind of change as the line above | CVE-2019-0803 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-08-14 | Ransomware use confirmed | CVE-2018-0802 | MicrosoftOffice CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Tue 11 Aug 2026· 1 change | |||||
| 2026-08-11 | Added to CISA KEV | CVE-2026-68820 | MicrosoftWindows Ancillary Function Driver for WinSock CISA KEV | fix due 2026-08-25 | Duration unknown |
| Mon 10 Aug 2026· 1 change | |||||
| 2026-08-10 | Ransomware use confirmed | CVE-2026-45659 | MicrosoftSharePoint Server CISA KEV | stated at publication Unknown, now states Known | Time to revision 40 days |
| Wed 22 Jul 2026· 1 change | |||||
| 2026-07-22 | Added to CISA KEV | CVE-2026-50522 | MicrosoftSharePoint CISA KEV | fix due 2026-07-25 | Duration unknown |
| Thu 16 Jul 2026· 1 change | |||||
| 2026-07-16 | Added to CISA KEV | CVE-2026-58644 | MicrosoftSharePoint CISA KEV | fix due 2026-07-19 | Duration unknown |
| Tue 14 Jul 2026· 2 changes | |||||
| 2026-07-14 | Added to CISA KEV | CVE-2026-56155 | MicrosoftActive Directory Federation Services CISA KEV | fix due 2026-07-28 | Duration unknown |
| 2026-07-14 | Added to CISA KEV | CVE-2026-56164 | MicrosoftSharePoint Server CISA KEV | fix due 2026-07-17 | Duration unknown |
| Wed 1 Jul 2026· 1 change | |||||
| 2026-07-01 | Added to CISA KEV | CVE-2026-45659 | MicrosoftSharePoint Server CISA KEV | fix due 2026-07-04 | Duration unknown |
| Mon 29 Jun 2026· 1 change | |||||
| 2026-06-29 | Ransomware use confirmed | CVE-2026-33825 | MicrosoftDefender CISA KEV | stated at publication Unknown, now states Known | Time to revision 68 days |
| Wed 20 May 2026· 6 changes | |||||
| 2026-05-20 | Added to CISA KEV | CVE-2010-0249 | MicrosoftInternet Explorer CISA KEV | fix due 2026-06-03 · listed 2026-06-03 | Duration unknown |
| 2026-05-20 | Added to CISA KEV | CVE-2008-4250 | MicrosoftWindows CISA KEV | fix due 2026-06-03 | Duration unknown |
| 2026-05-20 | Added to CISA KEV | CVE-2009-1537 | MicrosoftDirectX CISA KEV | fix due 2026-06-03 | Duration unknown |
| 2026-05-20 | Added to CISA KEV | CVE-2010-0806 | MicrosoftInternet Explorer CISA KEV | fix due 2026-06-03 | Duration unknown |
| 2026-05-20 | Added to CISA KEV | MicrosoftDefender | fix due 2026-06-03 | Duration unknown | |
| 2026-05-20 | same kind of change as the line above | CVE-2026-41091 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-05-20 | same kind of change as the line above | CVE-2026-45498 | same vendor as the line above | same change as the line above | Duration unknown |
| Fri 15 May 2026· 1 change | |||||
| 2026-05-15 | Added to CISA KEV | CVE-2026-42897 | MicrosoftMicrosoft CISA KEV | fix due 2026-05-29 | Duration unknown |
| Tue 28 Apr 2026· 1 change | |||||
| 2026-04-28 | Added to CISA KEV | CVE-2026-32202 | MicrosoftWindows CISA KEV | fix due 2026-05-12 | Duration unknown |
| Wed 22 Apr 2026· 1 change | |||||
| 2026-04-22 | Added to CISA KEV | CVE-2026-33825 | MicrosoftDefender CISA KEV | fix due 2026-05-06 | Duration unknown |
| Tue 21 Apr 2026· 1 change | |||||
| 2026-04-21 | Ransomware use confirmed | CVE-2023-21529 | MicrosoftExchange Server CISA KEV | stated at publication Unknown, now states Known | Time to revision 8 days |
| Tue 14 Apr 2026· 2 changes | |||||
| 2026-04-14 | Added to CISA KEV | CVE-2009-0238 | MicrosoftOffice CISA KEV | fix due 2026-04-28 | Duration unknown |
| 2026-04-14 | Added to CISA KEV | CVE-2026-32201 | MicrosoftSharePoint Server CISA KEV | fix due 2026-04-28 | Duration unknown |
| Mon 13 Apr 2026· 4 changes | |||||
| 2026-04-13 | Added to CISA KEV | CVE-2012-1854 | MicrosoftVisual Basic for Applications (VBA) CISA KEV | fix due 2026-04-27 | Duration unknown |
| 2026-04-13 | Added to CISA KEV | MicrosoftWindows | fix due 2026-04-27 | Duration unknown | |
| 2026-04-13 | same kind of change as the line above | CVE-2025-60710 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-04-13 | same kind of change as the line above | CVE-2023-36424 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-04-13 | Added to CISA KEV | CVE-2023-21529 | MicrosoftExchange Server CISA KEV | fix due 2026-04-27 | Duration unknown |
| Wed 18 Mar 2026· 1 change | |||||
| 2026-03-18 | Added to CISA KEV | CVE-2026-20963 | MicrosoftSharePoint CISA KEV | fix due 2026-03-21 | Duration unknown |
| Tue 17 Feb 2026· 1 change | |||||
| 2026-02-17 | Added to CISA KEV | CVE-2008-0015 | MicrosoftWindows CISA KEV | fix due 2026-03-10 | Duration unknown |
| Thu 12 Feb 2026· 1 change | |||||
| 2026-02-12 | Added to CISA KEV | CVE-2024-43468 | MicrosoftConfiguration Manager CISA KEV | fix due 2026-03-05 | Duration unknown |
| Tue 10 Feb 2026· 6 changes | |||||
| 2026-02-10 | Added to CISA KEV | MicrosoftWindows | fix due 2026-03-03 | Duration unknown | |
| 2026-02-10 | same kind of change as the line above | CVE-2026-21513 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-02-10 | same kind of change as the line above | CVE-2026-21525 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-02-10 | same kind of change as the line above | CVE-2026-21510 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-02-10 | same kind of change as the line above | CVE-2026-21533 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-02-10 | same kind of change as the line above | CVE-2026-21519 | same vendor as the line above | same change as the line above | Duration unknown |
| 2026-02-10 | Added to CISA KEV | CVE-2026-21514 | MicrosoftOffice CISA KEV | fix due 2026-03-03 | Duration unknown |
| Thu 29 Jan 2026· 2 changes | |||||
| 2026-01-29 | Ransomware use confirmed | CVE-2024-49039 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| 2026-01-29 | Ransomware use confirmed | CVE-2024-30088 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Mon 26 Jan 2026· 1 change | |||||
| 2026-01-26 | Added to CISA KEV | CVE-2026-21509 | MicrosoftOffice CISA KEV | fix due 2026-02-16 | Duration unknown |
| Tue 13 Jan 2026· 1 change | |||||
| 2026-01-13 | Added to CISA KEV | CVE-2026-20805 | MicrosoftWindows CISA KEV | fix due 2026-02-03 | Duration unknown |
| Wed 7 Jan 2026· 1 change | |||||
| 2026-01-07 | Added to CISA KEV | CVE-2009-0556 | MicrosoftOffice CISA KEV | fix due 2026-01-28 | Duration unknown |
| Tue 9 Dec 2025· 1 change | |||||
| 2025-12-09 | Added to CISA KEV | CVE-2025-62221 | MicrosoftWindows CISA KEV | fix due 2025-12-30 | Duration unknown |
| Wed 12 Nov 2025· 1 change | |||||
| 2025-11-12 | Added to CISA KEV | CVE-2025-62215 | MicrosoftWindows CISA KEV | fix due 2025-12-03 | Duration unknown |
| Fri 24 Oct 2025· 1 change | |||||
| 2025-10-24 | Added to CISA KEV | CVE-2025-59287 | MicrosoftWindows CISA KEV | fix due 2025-11-14 | Duration unknown |
| Mon 20 Oct 2025· 1 change | |||||
| 2025-10-20 | Added to CISA KEV | CVE-2025-33073 | MicrosoftWindows CISA KEV | fix due 2025-11-10 | Duration unknown |
| Tue 14 Oct 2025· 2 changes | |||||
| 2025-10-14 | Added to CISA KEV | MicrosoftWindows | fix due 2025-11-04 | Duration unknown | |
| 2025-10-14 | same kind of change as the line above | CVE-2025-24990 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-10-14 | same kind of change as the line above | CVE-2025-59230 | same vendor as the line above | same change as the line above | Duration unknown |
| Wed 8 Oct 2025· 1 change | |||||
| 2025-10-08 | Ransomware use confirmed | CVE-2024-21412 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Mon 6 Oct 2025· 4 changes | |||||
| 2025-10-06 | Added to CISA KEV | CVE-2010-3962 | MicrosoftInternet Explorer CISA KEV | fix due 2025-10-27 | Duration unknown |
| 2025-10-06 | Added to CISA KEV | MicrosoftWindows | fix due 2025-10-27 | Duration unknown | |
| 2025-10-06 | same kind of change as the line above | CVE-2021-43226 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-10-06 | same kind of change as the line above | CVE-2013-3918 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-10-06 | same kind of change as the line above | CVE-2011-3402 | same vendor as the line above | same change as the line above | Duration unknown |
| Tue 12 Aug 2025· 2 changes | |||||
| 2025-08-12 | Added to CISA KEV | CVE-2007-0671 | MicrosoftOffice CISA KEV | fix due 2025-09-02 | Duration unknown |
| 2025-08-12 | Added to CISA KEV | CVE-2013-3893 | MicrosoftInternet Explorer CISA KEV | fix due 2025-09-02 | Duration unknown |
| Tue 5 Aug 2025· 4 changes | |||||
| 2025-08-05 | Ransomware use confirmed | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Time to revision 15 days |
| 2025-08-05 | KEV required action changed | MicrosoftSharePoint | stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Time to revision 14 days | |
| 2025-08-05 | same kind of change as the line above | CVE-2025-49704 | same vendor as the line above | same change as the line above | Time to revision 14 days |
| 2025-08-05 | same kind of change as the line above | CVE-2025-49706 | same vendor as the line above | same change as the line above | Time to revision 14 days |
| 2025-08-05 | KEV required action changed | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | stated at publication CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. , now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Time to revision 15 days |
| Fri 25 Jul 2025· 2 changes | |||||
| 2025-07-25 | Ransomware use confirmed | MicrosoftSharePoint | stated at publication Unknown, now states Known | Time to revision 3 days | |
| 2025-07-25 | same kind of change as the line above | CVE-2025-49704 | same vendor as the line above | same change as the line above | Time to revision 3 days |
| 2025-07-25 | same kind of change as the line above | CVE-2025-49706 | same vendor as the line above | same change as the line above | Time to revision 3 days |
| Tue 22 Jul 2025· 2 changes | |||||
| 2025-07-22 | Added to CISA KEV | MicrosoftSharePoint | fix due 2025-07-23 | Duration unknown | |
| 2025-07-22 | same kind of change as the line above | CVE-2025-49704 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-07-22 | same kind of change as the line above | CVE-2025-49706 | same vendor as the line above | same change as the line above | Duration unknown |
| Mon 21 Jul 2025· 1 change | |||||
| 2025-07-21 | Added to CISA KEV | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | fix due 2025-07-21 · listed 2025-07-20 | Duration unknown |
| Fri 18 Jul 2025· 1 change | |||||
| 2025-07-18 | Ransomware use confirmed | CVE-2019-0708 | MicrosoftRemote Desktop Services CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Tue 13 May 2025· 7 changes | |||||
| 2025-05-13 | Added to CISA KEV | MicrosoftWindows | fix due 2025-06-03 | Duration unknown | |
| 2025-05-13 | same kind of change as the line above | CVE-2025-32709 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | same kind of change as the line above | CVE-2025-30397 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | same kind of change as the line above | CVE-2025-32706 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | same kind of change as the line above | CVE-2025-32701 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | same kind of change as the line above | CVE-2025-30400 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | Ransomware use confirmed | MicrosoftWindows | stated at publication Unknown, now states Known | Duration unknown | |
| 2025-05-13 | same kind of change as the line above | CVE-2022-21999 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-13 | same kind of change as the line above | CVE-2021-43890 | same vendor as the line above | same change as the line above | Duration unknown |
| Mon 12 May 2025· 3 changes | |||||
| 2025-05-12 | Ransomware use confirmed | MicrosoftWindows | stated at publication Unknown, now states Known | Duration unknown | |
| 2025-05-12 | same kind of change as the line above | CVE-2022-41091 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-12 | same kind of change as the line above | CVE-2022-30190 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-05-12 | same kind of change as the line above | CVE-2014-1812 | same vendor as the line above | same change as the line above | Duration unknown |
| Thu 17 Apr 2025· 1 change | |||||
| 2025-04-17 | Added to CISA KEV | CVE-2025-24054 | MicrosoftWindows CISA KEV | fix due 2025-05-08 | Duration unknown |
| Wed 9 Apr 2025· 1 change | |||||
| 2025-04-09 | Ransomware use confirmed | CVE-2025-29824 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Time to revision 1 days |
| Tue 8 Apr 2025· 1 change | |||||
| 2025-04-08 | Added to CISA KEV | CVE-2025-29824 | MicrosoftWindows CISA KEV | fix due 2025-04-29 | Duration unknown |
| Mon 7 Apr 2025· 3 changes | |||||
| 2025-04-07 | Ransomware use confirmed | CVE-2018-8639 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Time to revision 35 days |
| 2025-04-07 | Ransomware use confirmed | CVE-2024-38094 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| 2025-04-07 | Ransomware use confirmed | CVE-2024-30051 | MicrosoftDWM Core Library CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Mon 31 Mar 2025· 1 change | |||||
| 2025-03-31 | Ransomware use confirmed | CVE-2025-26633 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Time to revision 20 days |
| Tue 18 Mar 2025· 1 change | |||||
| 2025-03-18 | Ransomware use confirmed | CVE-2023-23376 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Duration unknown |
| Tue 11 Mar 2025· 6 changes | |||||
| 2025-03-11 | Added to CISA KEV | MicrosoftWindows | fix due 2025-04-01 | Duration unknown | |
| 2025-03-11 | same kind of change as the line above | CVE-2025-24993 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-03-11 | same kind of change as the line above | CVE-2025-24991 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-03-11 | same kind of change as the line above | CVE-2025-24985 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-03-11 | same kind of change as the line above | CVE-2025-24984 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-03-11 | same kind of change as the line above | CVE-2025-24983 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-03-11 | same kind of change as the line above | CVE-2025-26633 | same vendor as the line above | same change as the line above | Duration unknown |
| Mon 3 Mar 2025· 1 change | |||||
| 2025-03-03 | Added to CISA KEV | CVE-2018-8639 | MicrosoftWindows CISA KEV | fix due 2025-03-24 | Duration unknown |
| Tue 25 Feb 2025· 1 change | |||||
| 2025-02-25 | Added to CISA KEV | CVE-2024-49035 | MicrosoftPartner Center CISA KEV | fix due 2025-03-18 | Duration unknown |
| Fri 21 Feb 2025· 1 change | |||||
| 2025-02-21 | Added to CISA KEV | CVE-2025-24989 | MicrosoftPower Pages CISA KEV | fix due 2025-03-14 | Duration unknown |
| Tue 11 Feb 2025· 2 changes | |||||
| 2025-02-11 | Added to CISA KEV | MicrosoftWindows | fix due 2025-03-04 | Duration unknown | |
| 2025-02-11 | same kind of change as the line above | CVE-2025-21418 | same vendor as the line above | same change as the line above | Duration unknown |
| 2025-02-11 | same kind of change as the line above | CVE-2025-21391 | same vendor as the line above | same change as the line above | Duration unknown |
| Fri 7 Feb 2025· 1 change | |||||
| 2025-02-07 | Added to CISA KEV | CVE-2024-21413 | MicrosoftOffice Outlook CISA KEV | fix due 2025-02-27 · listed 2025-02-06 | Duration unknown |
| Tue 4 Feb 2025· 1 change | |||||
| 2025-02-04 | Added to CISA KEV | CVE-2024-29059 | Microsoft.NET Framework CISA KEV | fix due 2025-02-25 | Duration unknown |
Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →