EU Saw It FirstStanding
ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed
Updated 12 August 2026 · Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV
Of the 1,635 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.
Why it matters
KEV is the US default for 'confirmed exploited', but it is not the only source. Where the EUVD flags exploitation the KEV list has not, a KEV-only program is blind to real, active abuse.
What to do
- Security leaders. If you gate patching on KEV membership alone, add EUVD-exploited as a second confirmed-exploitation source.
- Lean IT orgs. A CVE the EU flags as exploited deserves KEV-level urgency even if CISA hasn't listed it yet.
- MSPs. For EU-facing clients, treat EUVD-exploited-not-KEV as an early exploitation warning.
Our take
Confirmed exploitation is not a single-source fact. Watching both catalogs catches abuse one alone misses.
Earlier issues
Past states of this signal, most recent first.
10 August 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed
Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV
Of the 1,631 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.
03 August 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed
Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV
Of the 1,620 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.
27 July 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed
Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV
Of the 1,616 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.