All patch & vulnerability trackers
Vulnerabilities exploited this week
The full exploited catalog is the exploited-CVE tracker; ranked next to the patches it is What's Hot; the whole picture is Senserva Live.
Every CVE that crossed from theoretical to confirmed exploited in the wild in the last 7 days: the newest CISA KEV catalog additions for July 2026, all vendors, enriched with CVSS and EPSS and flagged for ransomware use. Updated today and every day, multiple times daily, free, no sign-in.
Treat it as your today-view of the vendor security advisories that actually matter: if a CVE is on this page, someone is exploiting it right now, whether it lives in Cisco IOS XE, PAN-OS, Fortinet, Windows, or a package deep in your stack.
All 1,250+ exploited CVEs By vendor Microsoft patches CVE reference Patch Tuesday All trackers
Added to CISA KEV in the last 7 days
Every column sorts and searches. Click any row for the full description and links.
The last few weeks in exploitation
CISA confirmed 9 newly exploited vulnerabilities in the last 7 days, after 4 the week before and 9 across the two weeks before that: 23 new KEV entries in 30 days. Most-affected vendors this month: Microsoft, Ubiquiti, SonicWall, Cisco. Every entry below links to a Senserva page with the risk facts, the fix, and a validated AI read; our AI output follows the Senserva Trustworthy AI rules, every claim tied to a published feed fact.
This week's additions, at a glance
CVE-2023-4346 (KNX Association)CVE-2026-46817 (Oracle)CVE-2026-15409 (SonicWall)CVE-2026-15410 (SonicWall)CVE-2026-56155 (Microsoft)CVE-2026-56164 (Microsoft)CVE-2008-4128 (Cisco)CVE-2026-48939 (iCagenda)CVE-2026-56291 (Balbooa)
The 25 hottest CVEs right now
Ranked by confirmed exploitation (CISA KEV), ransomware use, EPSS, CVSS severity, and recency. The full list, CVEs and patches side by side: Hot Patches and CVEs, also a free JSON feed.
CVE-2026-48282CVE-2026-55255CVE-2008-4250CVE-2007-3010CVE-2012-0151CVE-2026-56290CVE-2014-1761CVE-2015-5122CVE-2026-34910CVE-2026-42897CVE-2026-45504CVE-2013-0631CVE-2016-0151CVE-2019-0808CVE-2013-3346CVE-2026-10520CVE-2019-1579CVE-2026-35273CVE-2012-0507CVE-2026-20253CVE-2019-2725CVE-2013-2465CVE-2021-30551CVE-2012-4681CVE-2026-12569
Sources and more info: CISA KEV catalog, FIRST.org EPSS, NIST NVD. On Senserva: the full exploited-CVE tracker, the Microsoft patch tracker, and free feeds and the JSON API (attribution: Patch Data Provided by Senserva).
Everything Siemserva by Senserva does, in one free run: your complete patch state ranked by real exploitation, all 650+ security checks across Microsoft 365, Intune, Defender, and Entra ID, and full reports you keep. Every user, every setting, every tenant you manage. Results land in an open database that stays yours, so you can write your own reports from it for as long as you like.
Start my free auditFree registration is all it takes. No card, no time limit on reading your results. Building something? The same patch and CVE data is a free feed and JSON API, no login.
Generated from this week's actual KEV additions, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.
The rest of the last 30 days
Every column sorts and searches. Click any row for the full description and links.
Full catalog, searchable with EPSS ranking and CISA due dates: the exploited-CVE tracker. Microsoft entries link to their CVE pages with the fixing KB.
Authoritative references
The primary sources this page is built from, and the ones worth bookmarking alongside it.
- CISA Known Exploited Vulnerabilities Catalog: the official catalog this page tracks, with federal remediation due dates.
- CISA KEV JSON feed: the official machine-readable catalog (CSV is on the catalog page).
- CISA Cybersecurity Advisories: the alerts that often accompany new KEV entries.
- CISA joint advisory: 2023 Top Routinely Exploited Vulnerabilities: the annual look-back companion to this live view.
- FIRST.org EPSS: the daily exploit-probability scores shown on each entry.
- NIST National Vulnerability Database: CVSS scoring and per-CVE detail for every entry.
- Microsoft Security Update Guide (MSRC): the authoritative fix record for the Microsoft entries.
- CVE Program (MITRE): the CVE identifiers themselves.
Frequently asked questions
Which vulnerabilities are being exploited this week?
The list above shows every CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog in the last 7 days, across all vendors. KEV means exploitation in the wild has been confirmed by CISA, not just predicted. The page refreshes three times a day: 5 AM, 12:30 PM, and 7 PM US Central.
What does it mean when a vulnerability is added to CISA KEV?
CISA has confirmed active exploitation and, for U.S. federal agencies, sets a remediation due date. For everyone else it is the strongest fix-first signal available: attackers are using it right now.
How is exploited this week different from a new CVE?
Thousands of CVEs are published every month, but only a small fraction are ever exploited. This page tracks the moment a CVE crosses from theoretical to actively exploited, which is usually when it should jump the patch queue.
How often is this page updated?
Multiple times daily from the CISA KEV catalog, enriched with CVSS and EPSS. When CISA adds new entries, they appear here the same day.
What was added to the CISA KEV catalog today?
The cards at the top of this page are the newest CISA KEV catalog additions, each with its date added. The page refreshes three times a day: 5 AM, 12:30 PM, and 7 PM US Central, so entries CISA adds today appear here the same day, with CVSS, EPSS, and ransomware context attached.
Which vendors show up most in the KEV catalog?
Cisco (including IOS XE and Identity Services Engine), Microsoft, Apple, Adobe, Google, Palo Alto Networks (PAN-OS), Fortinet, and Ivanti (including Pulse Connect Secure) are recurring names. Live per-vendor counts and a searchable list are on the exploited-CVE tracker.
Is there a CISA KEV JSON feed I can use?
CISA publishes the official KEV catalog as JSON and CSV on cisa.gov. Senserva also provides free JSON and RSS feeds of the enriched data, EPSS-ranked with no login, on the feeds page.
Is this the same as CISA's Top Routinely Exploited Vulnerabilities advisory?
No. That is an annual joint advisory listing the CVEs most exploited during a past year (the 2023 edition is the best known). This page tracks the live CISA KEV catalog: the moment a CVE is confirmed exploited, it is added and appears here. Both are CISA exploitation signals; this one moves daily.
Can I use this data with my own AI?
Yes. A free copy-paste AI prompt below the list is generated from this week's actual additions and carries the CVE names, vendors, CVSS, EPSS, and ransomware use into Claude, ChatGPT, or Copilot for triage in your own words.
Sponsored by Senserva
Siemserva by Senserva reports patch status for your own devices: which ones are missing the updates on this page, ranked by what attackers actually exploit.
- Patch status in one scan: which devices are affected, which are not
- Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
- Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
- Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
- Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
- Then go further: 650+ security checks find the drift management gaps across Microsoft 365, Intune, Defender, and Entra ID, with compliance evidence and Senserva Trustworthy AI remediation
Patching in action in two minutes. Watch page · All videos.
Triage order for this list
Same order in the dashboard, the report, and every AI answerRanked missing updates, fix-first order
27 findings · showing top 2| # | Update | CVE | Severity | Source | Devices | Waiting | |
|---|---|---|---|---|---|---|---|
| 1 | KB5040219 Windows 11 23H2 cumulative | CVE-2026-31210 KEV EPSS 0.94 | Critical | Defender | 41 | 19 days | Add to fix-first |
| 2 | KB5040088 .NET Framework security update | CVE-2026-29981 KEV | Critical | Intune | 17 | 12 days | Add to fix-first |
Ask Senserva
via Claude + MCPReference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (CISA KEV, NVD, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. All use of this data is subject to the Senserva EULA.
