Cyber Resilience

EU Saw It FirstStanding

ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed

Updated 12 August 2026 · Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV

100%Also on CISA KEV (1,629, 99.6%)EU-flagged only (6, 0.4%)
ENISA-flagged exploited CVEs: on KEV vs EU-only · security-resilience.ai

Of the 1,635 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.

Why it matters

KEV is the US default for 'confirmed exploited', but it is not the only source. Where the EUVD flags exploitation the KEV list has not, a KEV-only program is blind to real, active abuse.

What to do

Our take

Confirmed exploitation is not a single-source fact. Watching both catalogs catches abuse one alone misses.

Earlier issues

Past states of this signal, most recent first.

10 August 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed

Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV

100%Also on CISA KEV (1,625, 99.6%)EU-flagged only (6, 0.4%)

Of the 1,631 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.

03 August 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed

Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV

100%Also on CISA KEV (1,614, 99.6%)EU-flagged only (6, 0.4%)

Of the 1,620 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.

27 July 2026 ENISA flags 6 exploited CVEs that CISA's KEV hasn't listed

Timeframe: All EUVD exploited-flagged CVEs vs current CISA KEV

100%Also on CISA KEV (1,610, 99.6%)EU-flagged only (6, 0.4%)

Of the 1,616 CVEs ENISA's EU Vulnerability Database marks as exploited, 6 are not on CISA's Known Exploited Vulnerabilities catalog. A US-only exploitation feed misses these; the EU is flagging active abuse the KEV list hasn't caught.