These CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. They are confirmed to be actively exploited in the wild. Immediate remediation is strongly recommended.

Known Exploited VulnerabilitiesACTIVE THREATS

Vulnerabilities confirmed by CISA to be actively exploited. These should be prioritized for immediate patching and remediation in your environment.

3KEV Listed
3Critical
0High
⚠ KEV Catalog Entries (3)
CVE IDTitleSeverityCVSSKEV DateFix
CVE-2026-20127Cisco IOS XE Web UI Authentication Bypasscritical9.8Mar 15, 2026YES
CVE-2026-25108Unauthenticated Remote Code Execution in Acme Cloud Platformcritical9.8Mar 15, 2026YES
CVE-2025-49113Remote Code Execution in Apache Struts Framework via OGNL Expression Injectioncritical9.8Mar 15, 2025YES