{"built_from":{"fetched_at":"2026-08-23T05:46:48+00:00","kev":{"catalogVersion":"2026.08.21","dateReleased":"2026-08-21T17:46:43.6019Z","count":1674,"sha256":"137884960e3f801665bfa47694e703fbc4dd1c738df5e0e5af12d325a5f8a9d5","url":"https://raw.githubusercontent.com/cisagov/kev-data/main/known_exploited_vulnerabilities.json"},"attack":{"attack_version":"19.2","objects":26086,"types":{"x-mitre-collection":1,"campaign":56,"course-of-action":268,"intrusion-set":191,"malware":733,"tool":95,"attack-pattern":858,"x-mitre-matrix":1,"x-mitre-tactic":15,"x-mitre-analytic":1758,"x-mitre-data-component":109,"x-mitre-data-source":38,"x-mitre-detection-strategy":699,"relationship":21262,"identity":1,"marking-definition":1},"sha256":"dc1639caa5501d720e280cf1cbd8fbe009884a0c9b3e6e9ed9d0c25166c3d8f4","url":"https://raw.githubusercontent.com/mitre-attack/attack-stix-data/master/enterprise-attack/enterprise-attack.json"},"mappings":{"repo":"https://github.com/center-for-threat-informed-defense/mappings-explorer","commit":"705ca1b87954f9ff8d9eda62fb70b89939331407","commit_date":"2026-08-12T09:51:18-04:00","files":[{"file":"kev-02.13.2025_attack-15.1-enterprise.json","attack_version":"15.1","domain":"enterprise","kev_snapshot":"02/13/2025","mapping_objects":806,"distinct_cves":296},{"file":"kev-02.13.2025_attack-15.1-mobile.json","attack_version":"15.1","domain":"mobile","kev_snapshot":"02/13/2025","mapping_objects":8,"distinct_cves":3},{"file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","domain":"enterprise","kev_snapshot":"07/28/2025","mapping_objects":1183,"distinct_cves":419},{"file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","domain":"mobile","kev_snapshot":"07/28/2025","mapping_objects":45,"distinct_cves":14}]},"sigma":{"repo":"https://github.com/SigmaHQ/sigma","commit":"da9bb07d642a2826e89702445d32c795209ec108","commit_date":"2026-08-19T01:42:38+02:00","rules":3783},"capec":{"url":"https://raw.githubusercontent.com/mitre/cti/master/capec/2.1/stix-capec.json","patterns":615,"newest_modified":"2023-01-24T00:00:00.000Z","sha256":"ee6244f48259c1963d0507535e1843d67ba08fe58b4dfe351c1b74f9e376fa69"}},"kev":{"catalog_version":"2026.08.21","date_released":"2026-08-21T17:46:43.6019Z","count":1674,"empty_cwes":171,"empty_cwes_pct":10.2,"ransomware_known":352,"added_since_mapping_snapshot":283,"added_since_mapping_snapshot_mapped":0,"added_since_mapping_snapshot_mapped_pct":0.0,"newest_date_added":"2026-08-21"},"states":{"mapped":418,"stale":6,"unmapped":1250,"mapped_any":424,"mapped_any_pct":25.3,"unmapped_pct":74.7,"stale_pct_of_mapped":1.4,"mapped_exploitation_only":410,"mapped_exploitation_only_pct":24.5},"sigma_coverage":{"full":375,"partial":44,"none":0,"not_applicable_mobile_only":5,"none_pct_of_mapped":0.0,"mapped_techniques":152,"mapped_techniques_without_sigma":20,"live_techniques_with_strategy_without_sigma":297},"mappings":{"files":[{"file":"kev-02.13.2025_attack-15.1-enterprise.json","attack_version":"15.1","domain":"enterprise","kev_snapshot":"02/13/2025","last_update":"02/11/2025","capability_groups":{"access_ctrl":"Improper Access Control","auth_bypass":"Authentication Bypass","auth_missing":"Missing Authentication","buffer_overflow":"Buffer Overflow","code_execution":"Code Execution","code_injection":"Code Injection","command_execution":"Command Execution","command_injection":"Command Injection","default_cfg":"Default Configuration","dir_traversal":"Directory Traversal (Relative and Absolute)","dos":"Denial of Service","feature_bypass":"Security Feature Bypass","hardcoded_creds":"Hard-coded Credentials","inject":"Other Injection","input_validation":"Input Validation","int_overflow":"Integer Overflow","memory_corruption":"Memory Corruption","memory_mgmt":"Memory Management","oob":"Out-of-Bounds (Read and Write)","other":"Other","pointer_deref":"Pointer Dereference","pointer_vuln":"Other Pointer Vulnerability","priv_escalation":"Privilege Escalation","priv_mgmt":"Improper Privilege Management","race_condition":"Race Condition","resource_mgmt":"Resource Management","sandbox_bypass":"Sandbox Bypass or Escape","spoofing_vuln":"Spoofing Vulnerability","sql_injection":"SQL Injection","ssrf":"Server-Side Request Forgery (SSRF)","type_confusion":"Type Confusion","unrestricted_upload":"Unrestricted File Upload","untrusted_data":"Deserialization of Untrusted Data","use_after_free":"Use After Free","xss":"Cross-site Scripting (XSS)","xxe":"XML External Entity (XXE)"},"mapping_objects":806,"distinct_cves":296},{"file":"kev-02.13.2025_attack-15.1-mobile.json","attack_version":"15.1","domain":"mobile","kev_snapshot":"02/13/2025","last_update":"02/11/2025","capability_groups":{"buffer_overflow":"Buffer Overflow","input_validation":"Input Validation","use_after_free":"Use After Free"},"mapping_objects":8,"distinct_cves":3},{"file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","domain":"enterprise","kev_snapshot":"07/28/2025","last_update":"08/28/2025","capability_groups":{"access_ctrl":"Improper Access Control","auth_bypass":"Authentication Bypass","auth_missing":"Missing Authentication","buffer_overflow":"Buffer Overflow","code_execution":"Code Execution","code_injection":"Code Injection","command_execution":"Command Execution","command_injection":"Command Injection","default_cfg":"Default Configuration","dir_traversal":"Directory Traversal (Relative and Absolute)","dos":"Denial of Service","feature_bypass":"Security Feature Bypass","hardcoded_creds":"Hard-coded Credentials","inject":"Other Injection","input_validation":"Input Validation","int_overflow":"Integer Overflow","memory_corruption":"Memory Corruption","memory_mgmt":"Memory Management","oob":"Out-of-Bounds (Read and Write)","other":"Other","pointer_deref":"Pointer Dereference","pointer_vuln":"Other Pointer Vulnerability","priv_escalation":"Privilege Escalation","priv_mgmt":"Improper Privilege Management","race_condition":"Race Condition","resource_mgmt":"Resource Management","sandbox_bypass":"Sandbox Bypass or Escape","spoofing_vuln":"Spoofing Vulnerability","sql_injection":"SQL Injection","ssrf":"Server-Side Request Forgery (SSRF)","type_confusion":"Type Confusion","unrestricted_upload":"Unrestricted File Upload","untrusted_data":"Deserialization of Untrusted Data","use_after_free":"Use After Free","xss":"Cross-site Scripting (XSS)","xxe":"XML External Entity (XXE)"},"mapping_objects":1183,"distinct_cves":419},{"file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","domain":"mobile","kev_snapshot":"07/28/2025","last_update":"08/28/2025","capability_groups":{"buffer_overflow":"Buffer Overflow","input_validation":"Input Validation","use_after_free":"Use After Free","memory_corruption":"Memory Corruption","out_of_bounds":"Out-of-Bounds (Read and Write)","security_feature_bypass":"Security Feature Bypass","improper_access_control":"Improper Access Control","type_confusion":"Type Confusion"},"mapping_objects":45,"distinct_cves":14}],"latest_attack_version":"16.1","latest_kev_snapshot":"07/28/2025","distinct_cves":424,"mapping_objects":1229,"cves_only_in_older_file":[],"mapping_snapshot_iso":"2025-07-28","distinct_cves_in_kev":424,"distinct_cves_not_in_kev":[],"by_type":{"secondary_impact":329,"primary_impact":422,"exploitation_technique":478},"by_domain":{"enterprise":1184,"mobile":45},"cves_mobile_only":["CVE-2021-38000","CVE-2022-38181","CVE-2023-4863","CVE-2025-21479","CVE-2025-24200"],"techniques_referenced":152,"techniques_with_kev_cves":155},"attack":{"attack_version":"19.2","objects":26086,"techniques_total":858,"techniques_live":697,"techniques_live_without_detection_strategy":0,"detection_strategies":699,"detection_strategies_live":697,"detects_relationships":697,"analytics":1758,"analytics_live":1758,"data_components":109,"log_source_references":4182},"sigma":{"commit":"da9bb07d642a2826e89702445d32c795209ec108","commit_date":"2026-08-19T01:42:38+02:00","rules":3783,"rules_with_technique_tag":3312,"rules_with_cve_tag":208,"distinct_techniques":400,"distinct_cves":145,"cve_technique_pairs":199,"cves_in_pairs":126,"technique_tags_not_in_current_attack":[]},"log_sources":261,"capec":{"capec_version_note":"mitre/cti STIX mirror of CAPEC","capec_patterns":559,"capec_newest_modified":"2023-01-24","capec_with_attack_ref":177,"attack_techniques_reachable":189,"kev_with_cwe":1503,"kev_with_any_technique":497,"mean_techniques":7.5,"median_techniques":7,"max_techniques":51,"histogram":[{"n":1,"cves":59},{"n":2,"cves":18},{"n":3,"cves":89},{"n":4,"cves":47},{"n":5,"cves":4},{"n":6,"cves":28},{"n":7,"cves":116},{"n":8,"cves":58},{"n":9,"cves":5},{"n":10,"cves":3},{"n":11,"cves":5},{"n":12,"cves":7},{"n":13,"cves":0},{"n":14,"cves":0},{"n":15,"cves":0},{"n":16,"cves":0},{"n":17,"cves":0},{"n":18,"cves":0},{"n":19,"cves":0},{"n":20,"cves":0},{"n":21,"cves":0},{"n":22,"cves":0},{"n":23,"cves":0},{"n":24,"cves":0},{"n":25,"cves":33},{"n":26,"cves":24},{"n":27,"cves":0},{"n":28,"cves":0},{"n":29,"cves":0},{"n":30,"cves":1}],"top_techniques":[{"technique":"T1574.007","name":"Path Interception by PATH Environment Variable","cves":168,"pct":33.8},{"technique":"T1574.006","name":"Dynamic Linker Hijacking","cves":167,"pct":33.6},{"technique":"T1562.003","name":"Impair Command History Logging","cves":164,"pct":33.0},{"technique":"T1027","name":"Obfuscated Files or Information","cves":136,"pct":27.4},{"technique":"T1027.009","name":"Embedded Payloads","cves":135,"pct":27.2},{"technique":"T1539","name":"Steal Web Session Cookie","cves":128,"pct":25.8},{"technique":"T1553.002","name":"Code Signing","cves":125,"pct":25.2},{"technique":"T1036.001","name":"Invalid Code Signature","cves":123,"pct":24.7},{"technique":"T1027.006","name":"HTML Smuggling","cves":93,"pct":18.7},{"technique":"T1564.009","name":"Resource Forking","cves":93,"pct":18.7},{"technique":"T1083","name":"File and Directory Discovery","cves":66,"pct":13.3},{"technique":"T1574.010","name":"Services File Permissions Weakness","cves":64,"pct":12.9},{"technique":"T1548","name":"Abuse Elevation Control Mechanism","cves":60,"pct":12.1},{"technique":"T1040","name":"Network Sniffing","cves":53,"pct":10.7},{"technique":"T1134","name":"Access Token Manipulation","cves":49,"pct":9.9}],"overlap_with_ctid":{"chain_and_ctid_both_present":115,"share_at_least_one_technique":10,"share_none":105,"agree_pct":8.7}}}