Active Zero-Days 2026 — Most Exploited Vulnerabilities
Vulnerabilities confirmed as actively exploited in the wild, sourced live from CISA's Known Exploited Vulnerabilities catalog. Updated automatically.
Loading zero-day data from CISA KEV…
Frequently Asked Questions
What is a zero-day vulnerability?
A zero-day is a vulnerability being actively exploited by attackers before, or without, an official vendor patch being available — meaning defenders have had zero days of advance warning to prepare.
What is CISA's KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency of vulnerabilities confirmed to be actively exploited in real-world attacks.
How is a zero-day different from a regular CVE?
Every zero-day has a CVE identifier, but not every CVE is a zero-day. This page tracks specifically the subset confirmed as actively exploited, a much smaller and higher-priority list than the full CVE database.
How often is this list updated?
Automatically, whenever CISA publishes updates to the KEV catalog.
