This repository provides an up-to-date JSON and RSS feed of the Known Exploited Vulnerabilities (KEV) catalog maintained by CISA.
🕒 Last Updated: 2026-09-25 19:39:28 UTC
🕕 Kathmandu Time: 2026-09-26 01:24:28 NPT
| CVE ID | Vulnerability Name | Description |
|---|---|---|
| CVE-2026-67279 | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. |
| CVE-2026-65660 | Microsoft SharePoint Code Injection Vulnerability | Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability | WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local .php file outside the active theme directories, leading to remote code execution. |
- URL: CISA KEV JSON Feed
- This feed follows the JSON Feed format.
- URL: CISA KEV RSS Feed
- This RSS feed is useful for integrating with FreshRSS, RSS readers, and automation tools.
If you find any issues or have suggestions, feel free to open an issue or submit a pull request.
