THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative source for vulnerabilities exploited in the wild, aiding organizations in prioritizing their vulnerability management. The catalog provides a single repository for understanding significant vulnerabilities, including the recent CVE-2026-21962 affecting Oracle HTTP Server and Weblogic Server Proxy Plug-in, which presents improper access control risks.
Users are encouraged to apply mitigations as per vendor guidance and provide inputs for new vulnerabilities via a nomination link. The KEV catalog is available in multiple formats including CSV and JSON, and users can subscribe for updates.