THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by CISA to help organizations manage vulnerabilities exploited in the wild. The catalog serves as a resource for vulnerability management and prioritization. The latest entry is CVE-2026-72898, a SQL Injection vulnerability in Metabase that allows unauthenticated attackers to gain admin access, posing risks of data theft and manipulation.
Organizations are urged to follow mitigations per vendor instructions and comply with CISA's applicable security directives. The catalog is accessible in various formats, including CSV and JSON. Users can also subscribe for updates on the catalog.