State now. Changed: 0 tier promotions, +4 known-exploited vulnerability additions, 27 leak-site claims, and 0 confirmed breaches since yesterday.
Vulnerabilities and patches
Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers. A Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) listing or other confirmed exploitation never ranks below Act. Ransomware association reaches Act now; active exploitation can also rise one tier through either the end-of-life or open-exposure modifier.
Why now: this site build includes 1,690 actively exploited records; the ranked details below show their evidence and actions.
Choose your reading level
The page address stays the same, and this choice follows you to other pages.
Analyst view shows the full table.
State now
945 tracked CVEs are in the Act now tier in this site build.
Why these records matter
- CVE-2026-19490: Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09
- CVE-2018-9995: Exploit Prediction Scoring System probability jumped · 2026-09-12
- CVE-2017-8046: Exploit Prediction Scoring System probability jumped · 2026-09-12
- CVE-2018-2894: Exploit Prediction Scoring System probability jumped · 2026-09-12
- CVE-2018-0101: Exploit Prediction Scoring System probability jumped · 2026-09-12
What changed
This page does not publish a page-specific change count. Filter recent material changesor scan the daily comparison.
Details
The legend explains every priority and status label, and the filters sit beside the ranked records below.
Federal remediation deadline backlog
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.
Cloud provider flaws that never receive a CVE identifier.
Release cycles past End of Life. No patch is coming.
Compromised and typosquatted packages.
Advisories for operational technology and industrial control systems.
Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.
Public exploit code and proof-of-concepts.
An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.
The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.
What each badge means
- No signal currently raises the record above the baseline tier.
- A public exploit, elevated exploitation probability, or Stakeholder-Specific Vulnerability Categorization (SSVC) verdict raises this record for closer watching.
- The SSVC-style verdict calls for attention, but no confirmed exploitation signal sets an Act floor.
- Confirmed active exploitation or an SSVC-style Act verdict requires prompt action.
- Ransomware association sets the top tier; active exploitation can also rise one tier through the end-of-life or open-exposure modifier.
- Listed in the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog.
- Listed in the VulnCheck Known Exploited Vulnerabilities catalog as observed exploitation.
- Listed as exploited in the European Union Agency for Cybersecurity European Vulnerability Database.
- The CVE Numbering Authority that assigned or published information for the record.
- An Authorized Data Publisher that adds analysis to a CVE record without replacing the assigner.
- A severity score from the European Union Agency for Cybersecurity European Vulnerability Database, shown while NVD analysis is absent.
- The strongest exploitation state supported by the tracker signals for this vulnerability.
Tiers ascend Track (watch), Track* (a public exploit or a rising exploitation forecast), Attend (act in the normal cycle),Act (confirmed exploitation somewhere), and Act now(ransomware association, or active exploitation raised by the end-of-life or open-exposure modifier). A lower tier can never outrank a higher one. A Mentions count of 0 is a measured zero: the tracker looked and found no coverage, rather than not having looked.
| Changed | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09 | CitrixNetScaler | CRIT9.3v4.0 | 6%+2.2pp vs 7d ago | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 5 | Act now, 67 of 99Act now241st of 943 tracked, non-rejected CVEs in Act now | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | tbkvisiontbk-dvr4216_firmware | CRIT9.8v3.0 | 83%+17.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 64 of 99Act now372nd of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | VMwareSpring Framework | CRIT9.8v3.0 | 75%+20.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 63 of 99Act now399th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | OracleWebLogic Server | CRIT9.8v3.0 | 50%+26.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 63 of 99Act now407th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | CRIT10.0v3.0 | 87%+13.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 61 of 99Act now486th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | FortinetFortiOS | CRIT9.8v3.0 | 50%+13.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 60 of 99Act now537th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CitrixSD-WAN and NetScaler | CRIT9.8v3.0 | 43%+22.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 58 of 99Act now599th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CitrixSD-WAN and NetScaler | CRIT9.8v3.0 | 43%+22.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 58 of 99Act now600th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CitrixSD-WAN and NetScaler | CRIT9.8v3.0 | 40%+20.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 58 of 99Act now601st of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CitrixSD-WAN and NetScaler | CRIT9.8v3.0 | 40%+20.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 58 of 99Act now602nd of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | CitrixSD-WAN and NetScaler | CRIT9.8v3.0 | 39%+21.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 57 of 99Act now627th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | MicrosoftWindows | HIGH7.8v3.0 | 43%+14.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 55 of 99Act now680th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | MicrosoftWindows | HIGH7.8v3.0 | 63%+18.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 55 of 99Act now692nd of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08 | Not applicable outside CISA KEV | MicrosoftWindows | HIGH7.5v3.1 | 6%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 53 of 99Act now746th of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | MicrosoftWindows | MED5.3v3.1 | 48%+14.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 52 of 99Act now762nd of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08 | MicrosoftWindows | HIGH7.8v3.1 | 1%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 6 | Act now, 51 of 99Act now808th of 943 tracked, non-rejected CVEs in Act now | ||
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08 | MicrosoftWindows | HIGH7.8v3.1 | 1%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 4 | Act now, 50 of 99Act now828th of 943 tracked, non-rejected CVEs in Act now | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11 | Not applicable outside CISA KEV | FortinetFortiOS | MED4.8v3.1 | 0%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act now, 35 of 99Act now933rd of 943 tracked, non-rejected CVEs in Act now | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | MetabaseMetabase | CRIT10.0v4.0 | 94%+11.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | Act, 72 of 99Act1st of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | SimpleHelp SimpleHelp | CRIT9.5v4.0 | 64%+34.3pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 4 | Act, 71 of 99Act3rd of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Exploitation status turned active · 2026-09-09 | CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | CRIT10.0v3.1 | 76%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 6 | Act, 69 of 99Act25th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | MicrosoftSharePoint | CRIT9.1v3.1 | 51%+10.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 8 | Act, 69 of 99Act36th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-07 | AdobeCommerce and Magento | CRIT10.0v3.1 | 2%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 5 | Act, 67 of 99Act100th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma mappedAtomic mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | D-LinkDIR-820L | CRIT9.8v3.1 | 92%+11.6pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | Act, 66 of 99Act224th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | AppleiOS, iPadOS, and macOS | HIGH7.8v3.1 | 45%+29.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | Act, 65 of 99Act424th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | paperclipaipaperclip | CRIT10.0v3.1 | 19%+14.2pp vs 7d ago | VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | Act, 63 of 99Act602nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Red Hatdata_grid | CRIT9.8v3.0 | 86%+15.5pp vs 7d ago | VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 61 of 99Act842nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | gwolle_guestbook_projectgwolle_guestbook | CRIT9.0v3.0 | 37%+15.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 61 of 99Act847th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Exploitation status turned active · 2026-09-11A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-12News coverage surged · 2026-09-12 | GitLabCommunity Edition and Enterprise Edition | CRIT10.0v3.1CNA | 1%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 4 | Act, 60 of 99Act859th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-06Exploitation status turned active · 2026-09-07 | N-ableN-central | CRIT10.0v4.0 | 1%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 4 | Act, 60 of 99Act913th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | dellemc_idrac7 | CRIT9.8v3.0 | 90%+12.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act971st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | zeroshellzeroshell | CRIT9.8v3.0 | 90%+11.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act973rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | D-Linkdir-823_firmware | CRIT9.8v3.0 | 80%+14.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act990th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | ApacheSolr | CRIT9.8v3.0 | 78%+20.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act994th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | jpcertlogontracer | CRIT9.8v3.0 | 75%+17.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act999th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | belkincrock-pot_smart_slow_cooker_with_wemo_firmware | CRIT9.8v3.0 | 72%+12.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act1004th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08 | FortinetMultiple Products | HIGH8.1v3.1 | 2%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | Act, 59 of 99Act1033rd of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10 | Not applicable outside CISA KEV | salesagilitysuitecrm | CRIT10.0v3.1 | 6%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act1067th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | oturiasmart_google_code_inserter | CRIT9.8v3.0 | 91%+17.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act1086th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | asustoradm | CRIT9.8v3.0 | 44%+20.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act1152nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | wificamwireless_ip_camera_\(p2p\)_firmware | CRIT9.8v3.0 | 35%+21.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 59 of 99Act1175th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | xiongmaitechuc-httpd | CRIT9.8v3.0 | 29%+10.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1178th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | D-Linkcentral_wifimanager | HIGH8.6v3.0 | 44%+15.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1193rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Red HatJBoss Application Server | CRIT9.8v3.0 | 41%+15.8pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1194th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08 | Not applicable outside CISA KEV | XWikixwiki | CRIT9.9v3.1 | 92%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1201st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | ElasticKibana | CRIT9.8v3.0 | 82%+10.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1240th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | roxyfilemanroxy_fileman | CRIT9.8v3.0 | 73%+27.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1253rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | OracleWebLogic Server | CRIT9.8v3.0 | 71%+28.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1257th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | teltonikarut900_firmware | CRIT9.8v3.0 | 71%+10.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1261st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | TP-Linktl-wr840n_firmware | CRIT9.8v3.0 | 68%+36.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1265th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | QNAPQTS | CRIT9.8v3.0 | 66%+35.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1276th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | revive-sasrevive_adserver | CRIT9.8v3.0 | 57%+30.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1291st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | QNAPQTS | CRIT9.8v3.0 | 57%+16.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1292nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | LGsupersign_cms | CRIT9.8v3.0 | 56%+29.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1294th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | flowpaperflexpaper | CRIT9.8v3.0 | 53%+20.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1300th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | hootootripmate_titan_ht-tm05_firmware | CRIT9.8v3.0 | 48%+13.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1310th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | D-Linkdir-818lw_firmware | CRIT9.8v3.0 | 42%+19.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1319th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | aviary_image_editor_add-on_for_gravity_forms_projectaviary_image_editor_add-on_for_gravity_forms | CRIT9.8v3.0 | 41%+21.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1322nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | xiongmaitechuc-httpd | CRIT9.8v3.0 | 40%+21.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1325th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Zyxelusg40_firmware | CRIT9.8v3.1 | 95%+10.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1343rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | dreamboxopendreambox | CRIT9.8v3.0 | 22%+13.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1378th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | deltekmaconomy | CRIT9.8v3.0 | 84%+16.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 58 of 99Act1432nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | vBulletinvBulletin | CRIT9.8v3.0 | 68%+32.8pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1456th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | mlwebtechnologiesprayercenter | CRIT9.8v3.0 | 58%+20.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1472nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | zh_baidumap_projectzh_baidumap | CRIT9.8v3.0 | 58%+20.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1473rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Geutebruckip_camera_g-cam_efd-2250_firmware | CRIT9.8v3.0 | 52%+12.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1484th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | codemenschengift_vouchers | CRIT9.8v3.0 | 50%+26.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1492nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | wpenginewpgraphql | CRIT9.8v3.0 | 47%+27.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1495th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | dellemc_avamar | CRIT9.8v3.0 | 46%+26.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1497th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | gracemedia_media_player_projectgracemedia_media_player | CRIT9.8v3.0 | 44%+27.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1501st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | ApacheStruts | HIGH8.1v3.0 | 93%+10.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1508th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-10Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-05Exploitation status turned active · 2026-09-08 | MikroTikRouterOS | CRIT9.2v4.0 | 1%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 3 | Act, 57 of 99Act1531st of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | eatonintelligent_power_manager | CRIT9.8v3.0 | 17%+11.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1543rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | teclib-editiongestionnaire_libre_de_parc_informatique | CRIT9.8v3.0 | 23%+16.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1548th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | eq-3homematic_central_control_unit_ccu2_firmware | CRIT9.8v3.0 | 64%+15.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1638th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | barnimaster_ip_camera01_firmware | CRIT9.8v3.0 | 56%+15.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1648th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | jfrogartifactory | CRIT9.8v3.0 | 53%+35.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1654th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | cutephpcutenews | HIGH8.8v3.0 | 52%+11.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1655th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | seagateblackarmor_nas_220_firmware | CRIT9.8v3.0 | 51%+29.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1657th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | alibabafastjson | CRIT9.8v3.0 | 39%+22.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1686th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10 | Not applicable outside CISA KEV | varktechpricing_deals_for_woocommerce | CRIT9.8v3.1 | 8%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1712th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | calmar-webmediatotal_donations | CRIT9.8v3.0 | 26%+16.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 57 of 99Act1716th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | ntpsecntpsec | CRIT9.1v3.0 | 67%+30.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 56 of 99Act1792nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | WebminWebmin | HIGH8.8v3.0 | 35%+21.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 56 of 99Act1840th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | siteeditorsite_editor | HIGH7.5v3.0 | 62%+20.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 56 of 99Act1903rd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Exploitation status turned active · 2026-09-10 | ConnectWiseScreenConnect | CRIT9.9v3.1 | 1%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | Act, 56 of 99Act1907th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | supervisordsupervisor | HIGH8.8v3.0 | 87%+13.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 56 of 99Act1936th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | dasanzhoneznid_2426a_firmware | HIGH8.8v3.0 | 53%+10.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 56 of 99Act1966th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei not mapped | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-07 | Not applicable outside CISA KEV | esds.coemagic_data_center_management | HIGH8.8v3.1 | 34%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act1991st of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | huaweihg532_firmware | HIGH8.8v3.0 | 78%+11.8pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | Act, 55 of 99Act2009th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | MicrosoftEdge | HIGH7.5v3.0 | 67%+12.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2040th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mapped | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Exploitation status turned active · 2026-09-09 | GoogleChromium V8 | HIGH8.8v3.1 | 1%no prior reading | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 3 | Act, 55 of 99Act2124th of 4,325 tracked, non-rejected CVEs in Act | ||
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | jolokiawebarchive_agent | HIGH8.1v3.0 | 73%+25.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2139th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | grandnodegrandnode | HIGH7.5v3.0 | 57%+33.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2157th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | yawsyaws | HIGH7.5v3.0 | 81%+26.5pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2158th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | manageengineservicedesk | HIGH7.5v3.0 | 80%+27.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2162nd of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Zohomanageengine_opmanager | HIGH7.5v3.0 | 66%+20.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2175th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | helpdesk_pro_projecthelpdesk_pro | HIGH7.5v3.0 | 57%+29.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2185th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | Drupalavatar_uploader | HIGH7.5v3.0 | 56%+25.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 55 of 99Act2187th of 4,325 tracked, non-rejected CVEs in Act | |
| Permanent recordPoCSigma not mappedAtomic not mappedNuclei mapped | Exploit Prediction Scoring System probability jumped · 2026-09-12 | Not applicable outside CISA KEV | 99robotswp_background_takeover_advertisements | HIGH7.5v3.0 | 47%+24.2pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | Act, 54 of 99Act2195th of 4,325 tracked, non-rejected CVEs in Act | |
How scores and priority work
The effective Common Vulnerability Scoring System (CVSS) score uses NVD's latest version when present, otherwise CNA, ADP, then ENISA EUVD. A non-NVD score is labeled until NVD publishes its analysis. Priority is a tier first and a rank within that tier, never a raw sum, so the number is tier major: the five tiers ascend Track, Track*, Attend, Act, and Act now, and a lower-tier CVE can never outrank a higher-tier CVE. A CISA KEV listing or other confirmed exploitation sets an Act floor; ransomware association sets Act now. The Stakeholder-Specific Vulnerability Categorization (SSVC) verdict can set Track through Act. Its automatable and technical-impact foundation is the CISA Vulnrichment judgment where published, with a CVSS fallback; that verdict sets the base tier. Exploitation, open-exposure, and end-of-life modifiers can raise that tier and never lower it. A public exploit or elevated Exploit Prediction Scoring System (EPSS) result can set Track*. Open internet exposure raises an actively exploited or ransomware-associated item one tier and otherwise leaves it unchanged. End of Life raises an actively exploited item by at most one step and has no effect without active exploitation or ransomware association. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. All Tracked filters by published date; recent movement on an older CVE appears in Movers. If no authority published a date, the cell says so, shows first-tracked ingest provenance separately, and sorts below dated rows.
Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. No tracked exploitation signal: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.
Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.
Detection and validation: Sigma rule, Atomic test, Nuclei template, and Metasploit module badges report mapped metadata availability. They do not change priority.
What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.
Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA, ADP, or ENISA marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, a verified exploit published, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.
How this is computed
Published vulnerability records are ranked by priority tier first and by the documented evidence signals within that tier. The legend above names the source, window, and meaning of each field used by the table.
Method reviewed on .