CYBERSECURITYTRACKER
TRACKING4,887 stories929 vuln stories
Analyst view

Vulnerabilities and patches

Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers that put confirmed exploitation and internet-facing exposure first, then Exploit Prediction Scoring System (EPSS) likelihood, then how much attention it is getting in the news.

16,053 tracked1,685 in CISA KEV1,676 actively exploited
Skip to ranked Common Vulnerabilities and Exposures (CVE) table
Cloud Vulnerabilities

Cloud provider flaws that never receive a CVE identifier.

From the Open Cloud Vulnerability Database.277 tracked
End of Life

Products past end of support. No patch is coming.

From endoflife.date.632 past end of life
Malicious Packages

Compromised and typosquatted packages.

From OpenSSF and OSV.4,932 tracked
OT & ICS

Advisories for operational technology and industrial control systems.

From CISA.338 tracked
Patch Day

Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.

Exploits

Public exploit code and proof-of-concepts.

From Exploit-DB and VulnCheck.
128 matches

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.

Changed
CVE-2026-12569Exploit Prediction Scoring System probability jumped · 2026-08-29PTCWindchill and FlexPLMCRIT9.3v4.041%+10.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3573.4Act now27th of 816 tracked, non-rejected CVEs in Act now
CVE-2026-45659PoCExploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftSharePoint ServerHIGH8.8v3.176%+66.2pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4573.0Act now32nd of 816 tracked, non-rejected CVEs in Act now
CVE-2016-0034Exploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftSilverlightHIGH8.8v3.170%+11.1pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0568.5Act now195th of 816 tracked, non-rejected CVEs in Act now
CVE-2021-29441PoCExploit Prediction Scoring System probability jumped · 2026-08-29alibabanacosHIGH8.6v3.188%+18.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2566.1Act now274th of 816 tracked, non-rejected CVEs in Act now
CVE-2019-1068NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26Exploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftSQL ServerHIGH8.8v3.053%+19.8pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1561.3Act now437th of 816 tracked, non-rejected CVEs in Act now
CVE-2018-14665PoCExploit Prediction Scoring System probability jumped · 2026-08-29x.orgx_serverMED6.6v3.054%+26.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0559.0Act now499th of 816 tracked, non-rejected CVEs in Act now
CVE-2025-68686Exploit Prediction Scoring System probability jumped · 2026-08-29FortinetFortiOSMED5.9v3.129%+27.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2558.7Act now509th of 816 tracked, non-rejected CVEs in Act now
CVE-2015-3105Exploit Prediction Scoring System probability jumped · 2026-08-29AdobeFlash PlayerHIGH10.0v2.096%+13.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0558.6Act now513th of 816 tracked, non-rejected CVEs in Act now
CVE-2018-8011Exploit Prediction Scoring System probability jumped · 2026-08-29ApacheHTTP ServerHIGH7.5v3.077%+20.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0554.8Act now599th of 816 tracked, non-rejected CVEs in Act now
CVE-2026-48710PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26encodestarletteMED6.5v3.12%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2551.6Act now682nd of 816 tracked, non-rejected CVEs in Act now
CVE-2026-72898PoCExploit Prediction Scoring System probability jumped · 2026-08-29MetabaseMetabaseCRIT10.0v4.079%+68.8pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1472.0Act1st of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-63077PoCExploit Prediction Scoring System probability jumped · 2026-08-29JetBrainsTeamCityCRIT9.8v3.188%+77.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.5471.5Act2nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-73570PoCExploitation status turned active · 2026-08-22Exploit Prediction Scoring System probability jumped · 2026-08-29SynacorZimbra Collaboration Suite (ZCS)HIGH8.9v3.121%+19.5pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3469.6Act24th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-21962NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-24OracleHTTP Server and Oracle Weblogic Server Proxy Plug-inCRIT10.0v3.142%-1.2pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2469.6Act25th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-62593PoCExploit Prediction Scoring System probability jumped · 2026-08-29Ray-ProjectRayCRIT9.4v4.017%+15.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1469.3Act29th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-53690PoCExploit Prediction Scoring System probability jumped · 2026-08-29SitecoreMultiple ProductsCRIT9.0v3.151%+19.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0469.0Act35th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-18577Exploit Prediction Scoring System probability jumped · 2026-08-29N-ableN-centralHIGH8.2v4.054%+50.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.5468.9Act37th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-59310PoCExploit Prediction Scoring System probability jumped · 2026-08-29BroadcomVMware vCenterCRIT9.8v3.146%+43.5pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3468.6Act43rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-55040PoCExploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftSharePointCRIT9.1v3.140%+34.2pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.7468.2Act58th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-20333PoCExploit Prediction Scoring System probability jumped · 2026-08-29CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseCRIT9.9v3.171%+30.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0468.2Act59th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-9198PoCExploit Prediction Scoring System probability jumped · 2026-08-29IBMLangflowCRIT9.8v3.135%+16.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1468.1Act62nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-60004NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-25First tracked GiteaGiteaCRIT9.8v3.1ENISA85%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3468.0Act66th of 4,373 tracked, non-rejected CVEs in Act
CVE-2024-43468PoCExploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftConfiguration ManagerCRIT9.8v3.182%+20.6pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0467.0Act109th of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-21551PoCExploit Prediction Scoring System probability jumped · 2026-08-29Delldbutil DriverHIGH8.8v3.179%+26.1pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1466.9Act167th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-68645PoCExploit Prediction Scoring System probability jumped · 2026-08-29Synacor Zimbra Collaboration Suite (ZCS)HIGH8.8v3.149%+14.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0466.1Act231st of 4,373 tracked, non-rejected CVEs in Act
CVE-2018-19410PoCExploit Prediction Scoring System probability jumped · 2026-08-29PaesslerPRTG Network MonitorCRIT9.8v3.198%+11.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0466.1Act232nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-21224PoCExploit Prediction Scoring System probability jumped · 2026-08-29GoogleChromium V8HIGH8.8v3.184%+27.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0466.0Act242nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2019-13720PoCExploit Prediction Scoring System probability jumped · 2026-08-29GoogleChrome WebAudioHIGH8.8v3.173%+23.8pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0465.8Act252nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-23209Exploit Prediction Scoring System probability jumped · 2026-08-29Craft CMSCraft CMSHIGH8.0v3.122%+17.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.9Act403rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2012-1856Exploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftOfficeHIGH8.8v3.172%+10.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.7Act429th of 4,373 tracked, non-rejected CVEs in Act
CVE-2015-2502Exploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftInternet ExplorerHIGH8.8v3.151%+12.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.7Act432nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2023-49105NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-27Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26ownCloudownCloudCRIT9.8v3.141%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1464.7Act433rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2020-10221PoCExploit Prediction Scoring System probability jumped · 2026-08-29rConfigrConfigHIGH8.8v3.180%+43.5pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.6Act440th of 4,373 tracked, non-rejected CVEs in Act
CVE-2020-13671PoCExploit Prediction Scoring System probability jumped · 2026-08-29DrupalDrupal coreHIGH8.8v3.135%+31.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.6Act443rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-18556Exploit Prediction Scoring System probability jumped · 2026-08-29N-ableN-centralHIGH8.2v4.040%+39.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1464.5Act452nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2019-2215PoCExploit Prediction Scoring System probability jumped · 2026-08-29AndroidAndroid KernelHIGH7.8v3.172%+28.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0464.1Act519th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-40536Exploit Prediction Scoring System probability jumped · 2026-08-29SolarWindsWeb Help DeskHIGH8.1v3.182%+10.1pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1463.9Act538th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-6875Exploit Prediction Scoring System probability jumped · 2026-08-29ServiceNowServiceNow AI PlatformCRIT9.5v4.078%+50.8pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3463.1Act638th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-9377Exploit Prediction Scoring System probability jumped · 2026-08-29TP-LinkMultiple RoutersHIGH8.6v4.034%+21.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0462.6Act706th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-66066PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-25Exploit Prediction Scoring System probability jumped · 2026-08-29railsActive StorageCRIT9.5v4.028%+26.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3461.9Act781st of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-23758NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26Ajax.NET ProfessionalAjax.NET ProfessionalHIGH8.1v3.184%-5.1pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1461.8Act786th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-34486PoCExploit Prediction Scoring System probability jumped · 2026-08-29ApacheTomcatHIGH7.5v3.199%+15.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3461.5Act810th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-61511PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27Exploit Prediction Scoring System probability jumped · 2026-08-29vBulletinvBulletinCRIT9.3v4.071%+69.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0461.1Act852nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-16723PoCExploit Prediction Scoring System probability jumped · 2026-08-29AlibabaFastjsonCRIT9.0v3.116%+15.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2460.3Act909th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-46442PoCExploit Prediction Scoring System probability jumped · 2026-08-29FlowiseAIFlowiseCRIT9.4v4.036%+32.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0459.8Act958th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-34027PoCExploit Prediction Scoring System probability jumped · 2026-08-29Versa NetworksVersa Concerto SD-WAN Orchestration PlatformCRIT10.0v4.045%+12.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0459.8Act959th of 4,373 tracked, non-rejected CVEs in Act
CVE-2020-36847PoCExploit Prediction Scoring System probability jumped · 2026-08-29simplefilelistsimple_file_listCRIT9.8v3.132%+14.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0459.6Act966th of 4,373 tracked, non-rejected CVEs in Act
CVE-2024-21182PoCExploit Prediction Scoring System probability jumped · 2026-08-29OracleWebLogic ServerHIGH7.5v3.174%+24.2pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0459.4Act1026th of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-20124PoCExploit Prediction Scoring System probability jumped · 2026-08-29DrayTekVigorConnectHIGH7.5v3.196%+25.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1459.3Act1062nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2022-0995NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26LinuxKernelHIGH7.8v3.110%+3.3pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1459.1Act1093rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-20123PoCExploit Prediction Scoring System probability jumped · 2026-08-29DrayTekVigorConnectHIGH7.5v3.190%+14.8pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1458.9Act1109th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-28137PoCExploit Prediction Scoring System probability jumped · 2026-08-29totolinka810r_firmwareCRIT9.8v3.136%+22.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0458.7Act1168th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-32201PoCExploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftSharePoint ServerMED6.5v3.143%+20.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2458.6Act1196th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-28318PoCExploit Prediction Scoring System probability jumped · 2026-08-29SolarWindsServ-UHIGH7.5v3.140%+31.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0458.4Act1224th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-8452NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26CitrixNetScaler ADC and NetScaler GatewayHIGH8.8v4.02%+0.6pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2458.3Act1237th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-53435PoCExploit Prediction Scoring System probability jumped · 2026-08-29JenkinsjenkinsHIGH8.8v3.153%+34.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0457.9Act1375th of 4,373 tracked, non-rejected CVEs in Act
CVE-2021-27691Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22Tendag0_firmwareCRIT9.8v3.125%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0457.8Act1403rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2022-47945PoCExploit Prediction Scoring System probability jumped · 2026-08-29thinkphpThinkPHPCRIT9.8v3.128%+11.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0457.6Act1447th of 4,373 tracked, non-rejected CVEs in Act
CVE-2023-34132Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26SonicWallanalyticsCRIT9.8v3.18%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1457.5Act1488th of 4,373 tracked, non-rejected CVEs in Act
CVE-2018-4404PoCExploit Prediction Scoring System probability jumped · 2026-08-29Appleiphone_osHIGH8.8v3.138%+23.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0457.5Act1493rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-25253PoCExploit Prediction Scoring System probability jumped · 2026-08-29openclawopenclawHIGH8.8v3.124%+15.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0456.4Act1795th of 4,373 tracked, non-rejected CVEs in Act
CVE-2018-4237PoCExploit Prediction Scoring System probability jumped · 2026-08-29Appleiphone_osHIGH7.8v3.034%+20.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0456.1Act1882nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-49869PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26kestrakestraCRIT10.0v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1455.1Act2101st of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-74233Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27ZbtlinkWE1326CRIT9.3v4.03%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1455.1Act2118th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-18963PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-25Red Hatbuild_of_keycloakCRIT9.1v3.13%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1455.0Act2134th of 4,373 tracked, non-rejected CVEs in Act
CVE-2018-1000001PoCExploit Prediction Scoring System probability jumped · 2026-08-29GNUGNU C Library (glibc)HIGH7.8v3.028%+15.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454.9Act2146th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-46300PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26LinuxKernelHIGH7.8v3.19%+2.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1454.9Act2150th of 4,373 tracked, non-rejected CVEs in Act
CVE-2022-41800PoCExploit Prediction Scoring System probability jumped · 2026-08-29F5big-ip_access_policy_managerHIGH8.7v3.177%+11.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454.7Act2188th of 4,373 tracked, non-rejected CVEs in Act
CVE-2018-1000049PoCExploit Prediction Scoring System probability jumped · 2026-08-29nanopoolclaymore_dual_minerHIGH7.5v3.075%+17.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454.6Act2222nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-63520PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-25MicrosoftMicrosoft SharePoint Enterprise Server 2016HIGH8.1v3.13%+1.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3454.6Act2228th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-71257PoCExploit Prediction Scoring System probability jumped · 2026-08-29BMC Software, Inc.FootPrintsMED6.9v4.045%+39.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1452.5Act2570th of 4,373 tracked, non-rejected CVEs in Act
CVE-2015-3246NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26Red HatLibuserHIGH7.2v2.09%+1.7pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1452.0Act2642nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2015-5287NEWPoCAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-26Red HatAutomatic Bug Reporting ToolMED6.9v2.05%+1.6pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1452.0Act2647th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-77136Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-25TYPO3Extension "powermail"CRIT9.5v4.01%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0450.0Act2955th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-53362NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-27Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27Exploitation status turned active · 2026-08-27LinuxKernelHIGH7.8v3.11%+0.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1449.9Act2982nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-19632PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-25TranslatePressTranslatePress – Translate Multilingual sites with AI TranslationCRIT9.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0449.6Act3051st of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-78003Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-28MailgunMailgun for WordPressCRIT9.8v3.11%+0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0447.4Act3401st of 4,373 tracked, non-rejected CVEs in Act
CVE-2011-4106Exploit Prediction Scoring System probability jumped · 2026-08-29binarymoontimthumbMED6.8v2.023%+11.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0446.9Act3476th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-31635PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26LinuxKernelHIGH7.5v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0446.6Act3514th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-74232Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27ZbtlinkL3_V2_8CRIT9.3v4.00%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1445.5Act3652nd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-46331PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26LinuxKernelHIGH7.8v3.11%+0.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0443.5Act3830th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-57739Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCRIT9.3v3.10%+0.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0443.0Act3880th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-18781PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-24Contact Form 7Drag and Drop Multiple File UploadHIGH8.1v3.10%0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0442.2Act3944th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-32558Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-24RedefiningTheWebAffiliate Pro - Affiliate Program for WooCommerce & WordPressCRIT9.8v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0442.0Act3961st of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-66384NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-27Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27Exploitation status turned active · 2026-08-27JFrogArtifactoryMED5.3v3.11%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0440.3Act4075th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-43494PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26LinuxKernelHIGH7.8v3.10%0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0439.2Act4131st of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-82078Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-28PaperCutPaperCut MF/NGCRIT9.4v4.0VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0438.5Act4173rd of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-36425PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-26OPSWATAppRemover DriverMED6.5v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0436.4Act4256th of 4,373 tracked, non-rejected CVEs in Act
CVE-2025-10164PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22lmsyssglangMED5.5v4.00%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0435.2Act4290th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-81578Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-28PaperCutPaperCut MF/NGHIGH8.8v4.0VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0433.2Act4326th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-16747PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-24ThemeumKirkiMED6.5v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0432.5Act4338th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-16759Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-28First tracked themeumtutor_lmsN/A0%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0426.6Act4364th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-76581Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-27First tracked wpmudevWPMU DEV DashboardN/A0%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0424.9Act4365th of 4,373 tracked, non-rejected CVEs in Act
CVE-2026-71362Exploit Prediction Scoring System probability jumped · 2026-08-29AdobeAdobe CommerceCRIT9.1v3.125%+23.8pp vs 7d agoTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.3238.1Track*35th of 2,100 tracked, non-rejected CVEs in Track*
CVE-2026-33112Exploit Prediction Scoring System probability jumped · 2026-08-29MicrosoftMicrosoft SharePoint Enterprise Server 2016HIGH8.8v3.133%+29.6pp vs 7d agoTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0236.3Track*86th of 2,100 tracked, non-rejected CVEs in Track*
CVE-2026-81826A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-27flowintelflowintelCRIT9.1v4.0CNA0%no prior readingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0122.3Track2433rd of 8,491 tracked, non-rejected CVEs in Track
CVE-2026-81719A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-27jahlivesopenssl_encryptCRIT9.3v4.0CNA0%no prior readingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0122.3Track2442nd of 8,491 tracked, non-rejected CVEs in Track
CVE-2026-81698A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-27jahlivesopenssl_encryptCRIT9.3v4.0CNA0%no prior readingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0121.7Track2782nd of 8,491 tracked, non-rejected CVEs in Track
CVE-2026-81690A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-27jahlivesopenssl_encryptHIGH8.7v4.0CNA0%no prior readingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.3Track3641st of 8,491 tracked, non-rejected CVEs in Track
CVE-2026-81093A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-27apifyactors-mcp-serverHIGH8.7v4.0CNA0%no prior readingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track3717th of 8,491 tracked, non-rejected CVEs in Track
How scores and priority work

The effective Common Vulnerability Scoring System (CVSS) score uses a strict precedence: the National Vulnerability Database (NVD) score when present (latest version, v4.0 then v3.1, v3.0, and v2.0), else the CVE Numbering Authority (CNA) score from the CVE record, else the Authorized Data Publisher (ADP) score. A CNA or ADP score is labeled with a chip beside the version chip; once NVD publishes its analysis the score is replaced and relabeled. Priority is a tier first and a rank within that tier, never a raw sum, so the number is tier major: the five tiers ascend Track, Track*, Attend, Act, and Act now, and any Act now item outranks any Act item, so a quiet high severity CVE can never outrank one that is actively exploited and internet facing. The tier is set by exploitation first, on a single ladder from proof of concept up through active and ransomware use that the tracked exploitation catalogs and the CISA Vulnrichment exploitation signal feed rather than stack, then a Stakeholder Specific Vulnerability Categorization (SSVC) style decision computed by this tracker, whose foundation is the CISA Vulnrichment program's published SSVC judgments wherever they have been ingested for the CVE, with the automatability and technical impact inputs derived here from CVSS only where no CISA judgment is stored (those two inputs are labeled with their source on the CVE panel), then exposure, then Exploit Prediction Scoring System (EPSS) probability. The exploitation ladder, exposure, and End of Life only ever raise the tier above what that SSVC decision implies, never lower it. Exposure counts as open only when the attack vector is Network and the product is a curated internet facing class such as a firewall, a virtual private network gateway, or an edge router, never from Network alone. End of Life raises the tier by at most one step, and only when the product is both internet facing exposed and actively exploited, never on its own. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. The All Tracked view filters on a published-date window: a segment shows only CVEs published within it, so the default view shows what is genuinely new rather than years-old maximum-priority entries; Movers is unchanged. The Published column shows only a date an authority stated (NVD or the CVE record); a CVE tracked here without one shows a dash, with the first-tracked date in the dash's tooltip, and sorts below every dated row. The window segments filter on the CVE's published date, whatever its provenance; recent movement on older CVEs, such as a fresh CISA KEV addition to an old CVE, appears in Movers, not in the windows.

Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. Dash: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.

Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.

Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA or ADP marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.