THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by CISA to assist the cybersecurity community in managing vulnerabilities that are actively exploited. It helps organizations prioritize their vulnerability management strategies. The catalog includes a case for CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter that could allow arbitrary code execution. Users are urged to follow vendor instructions for mitigation and comply with CISA's guidance on security updates.
The KEV Catalog is accessible in various formats, including CSV and JSON, and organizations can nominate new vulnerabilities for inclusion.