THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative resource for vulnerabilities that have been actively exploited in the field, aiding cybersecurity professionals in vulnerability management. Users are encouraged to report any exploited vulnerabilities not listed in the catalog. The catalog includes details on CVE-2026-33824, a Microsoft Internet Key Exchange (IKE) Service Extensions vulnerability that may allow remote code execution.
Organizations should apply vendor-mitigated actions and comply with CISA directives for risk management. The KEV catalog is available in CSV and JSON formats, and users can subscribe for updates.